Table 81: Firewall Filter Match Conditions for VPLS Traffic (continued)
Description
Match Condition
(MX Series routers and EX Series switches only) IP address of the source node sending the packet.
Note that when using this term, the match condition ether-type IPv4 must also be defined on
the same term.
ip-source-address address
(MX Series only) Match the IPv6 source address in a named-list.ipv6-source-prefix-list
named-list
(MX Series and EX9200 only) 128-bit address that supports the standard syntax for IPv6
addresses. Starting in Junos OS 14.2, firewall family bridge IPv6 match criteria is supported on
MX Series and EX9200 switches.
ipv6-address address
((MX Series and EX9200 only) 128-bit address that is the final destination node address for this
packet. Note that when using this term, the match condition ether-type IPv6 must be defined on
the same term.
ipv6-destination-address
address
(MX Series only) Match the IPv6 destination addresses in a named-list.ipv6-destination-prefix-list
named-list
(MX Series only) Match IPv6 next header protocol type.
The following list shows the supported values for protocol:
•
ah—IP Security authentication header
•
dstopts—IPv6 destination options
•
egp—Exterior gateway protocol
•
esp—IPSec Encapsulating Security Payload
•
fragment—IPv6 fragment header
•
gre—Generic routing encapsulation
•
hop-by-hop—IPv6 hop by hop options
•
icmp—Internet Control Message Protocol
•
icmp6—Internet Control Message Protocol Version 6
•
igmp—Internet Group Management Protocol
•
ipip—IP in IP
•
ipv6—IPv6 in IP
•
no-next-header—IPv6 no next header
•
ospf—Open Shortest Path First
•
pim—Protocol Independent Multicast
•
routing—IPv6 routing header
•
rsvp—Resource Reservation Protocol
•
sctp—Stream Control Transmission Protocol
•
tcp—Transmission Control Protocol
•
udp—User Datagram Protocol
•
vrrp—Virtual Router Redundancy Protocol
ipv6-next-header protocol
(MX Series only) Do not match the IPv6 next header protocol type.ipv6-next-header-except
protocol
1075Copyright © 2017, Juniper Networks, Inc.
Chapter 32: Configuring Firewall Filters