SRX

Expand all | Collapse all

Filter based Forwading based on other except ip address?

Jump to Best Answer
  • 1.  Filter based Forwading based on other except ip address?

    Posted 08-20-2017 04:32

    Hi All,

     

     

    Usually i'm do FBF based on source ip address only. But may i know whether FBF can do based on below:

     

    a.) Applications

    b.) AD / User Group

    c.) Zone

    d.) Interface

     

     

    Thanks and appreciate someone feedback



  • 2.  RE: Filter based Forwading based on other except ip address?

    Posted 08-20-2017 05:21

    It can do based on Applications(Port number) but not based on Zone or User group. FBF will be applied to Interface where you want to do forwarding so matching interface in filter is not needed. But firewall filter does provide Interface as term to choose. IP address, Protocol, Port, IP options, TCP flags, DSCP are the various filters to match when using firewall filter.  You can goto firewall filter and hit ? to get various possible fields to match with. 



  • 3.  RE: Filter based Forwading based on other except ip address?

    Posted 08-20-2017 06:03

    Hello,

     

    To add to what has been already answered:

     

    a) FBF on application - You could possibly do it indirectly:

    1/ let AppQoS tag Your packets with Forwarding Class

    https://www.juniper.net/documentation/en_US/junos/topics/example/application-qos-configuring.html

    2/ do output FBF based on Forwarding Class.

    Obviously, You have to sacrifice a FC per application or group of applications.

     

    Disclaimer - I haven't tested this myself.

    HTH

    Thx
    Alex



  • 4.  RE: Filter based Forwading based on other except ip address?

    Posted 08-20-2017 06:48

    Hi all,

     

    Thanks for the feedback. Its look like when i'm use "term 1 from ?" the zone and AD not not have.

     

    Thanks again for your help.



  • 5.  RE: Filter based Forwading based on other except ip address?

    Posted 08-20-2017 07:51
    As mentioned eariler, zone and user group options are not available. You cannt match based on them.


  • 6.  RE: Filter based Forwading based on other except ip address?
    Best Answer

    Posted 08-20-2017 07:51
    As mentioned eariler, zone and user group options are not available. You cannt match based on them.