category {
values [category-value];
}
direction {
expression (and | or);
values [any client-to-server exclude-any exclude-client-to-server
exclude-server-to-client server-to-client];
}
false-positives {
values [frequently occasionally rarely unknown];
}
performance {
values [fast normal slow unknown];
}
products {
values [product-value];
}
recommended;
no-recommended;
service {
values [service-value];
}
severity {
values [critical info major minor warning];
}
type {
values [anomaly signature];
}
}
}
idp-policy policy-name {
rulebase-exempt {
rule rule-name {
description text;
match {
attacks {
custom-attack-groups [attack-group-name];
custom-attacks [attack-name];
dynamic-attack-groups [attack-group-name];
predefined-attack-groups [attack-group-name];
predefined-attacks [attack-name];
}
destination-address ([address-name] | any | any-ipv4 | any-ipv6);
destination-except [address-name];
from-zone (zone-name | any );
source-address ([address-name] | any | any-ipv4 | any-ipv6);
source-except [address-name];
to-zone (zone-name | any);
}
}
}
rulebase-ips {
rule rule-name {
description text;
match {
application (application-name | any | default);
83Copyright © 2016, Juniper Networks, Inc.
Chapter 11: Configuration Statements