Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation

Applying the Filter or Service Set to the Interface Receiving Traffic to Be Secured

For the ES PIC, apply your firewall filter on the input interface receiving the traffic that you wish to send to the IPSec tunnel. To do this, include the filter statement at the [edit interfaces interface-name unit unit-number family inet] hierarchy level.

[edit interfaces interface-name unit unit-number family inet]filter {input filter-name;}

For the AS and MultiServices PICs, apply your IPSec-based interface service set to the input interface receiving the traffic that you wish to send to the IPSec tunnel. To do this, include the service-set service-set-name statement at the [edit interfaces interface-name unit unit-number family inet service (input | output)] hierarchy level.

[edit interfaces interface-name unit unit-number family inet]service {input {service-set service-set-name;}output {service-set service-set-name;}}

To configure a next-hop-based service set on the AS and MultiServices PICs, include the service-domain statement at the [edit interfaces interface-name unit unit-number] hierarchy level and specify one logical interface on the AS PIC as an inside interface and a second logical interface on the AS PIC as an outside interface.

[edit interfaces sp-fpc/pic/port]unit 0 {family inet {address ip-address;}}unit 1 {family inet;service-domain inside;}unit 2 {family inet;service-domain outside;}

Published: 2012-11-28

Supported Platforms

Published: 2012-11-28