See the following sections:
- match {
- destination-address destination-address
;
- destination-port port-number ;
- source-address [source-address];
- }
- [edit security nat destination
rule-set rule-set-name rule rule-name ]
Statement introduced in Release 9.2 of JUNOS software.
Specify the destination rules to be used as match criteria.
This statement is supported on SRX-series devices.
The remaining statements are explained separately.
For configuration instructions and examples, see the JUNOS Software Security Configuration Guide.
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.
- match {
-
- attacks {
- custom-attacks [ attack-name
];
- predefined-attack-groups
[ attack-name ];
- predefined-attacks [ attack-name
];
- }
- destination-address [ address-name
];
- destination-except [ address-name
];
- from-zone zone-name ;
- source-address [ address-name
];
- source-except [ address-name
];
- to-zone
zone-name ;
- }
- [edit security idp idp-policy policy-name rulebase-exempt rule rule-name ],
- [edit security idp idp-policy policy-name rulebase-ips rule rule-name ]
Statement introduced in Release 9.2 of JUNOS software.
Specify the rules to be used as match criteria.
This statement is supported on SRX-series devices.
The remaining statements are explained separately.
For configuration instructions and examples, see the JUNOS Software Security Configuration Guide.
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.
- match {
- application [ application-name-or-set
];
-
- destination-address {
-
address-name ;
- }
-
- source-address {
-
address-name ;
- }
- }
- [edit security policies from-zone zone-name to-zone zone-name policy policy-name]
Statement introduced in Release 8.5 of JUNOS software.
Configure security policy match criteria.
This statement is supported on J-series and SRX-series devices.
The remaining statements are explained separately.
For configuration instructions and examples, see the JUNOS Software Security Configuration Guide.
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.
- match {
- destination-address [destination-address];
- source-address [source-address];
- }
- [edit security nat source
rule-set rule-set-name rule rule-name ]
Statement introduced in Release 9.2 of JUNOS software.
Specify the source rules to be used as match criteria.
This statement is supported on SRX-series devices.
The remaining statements are explained separately.
For configuration instructions and examples, see the JUNOS Software Security Configuration Guide.
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.
- match {
- destination-address [destination-address];
- }
- [edit security nat static
rule-set rule-set-name rule rule-name ]
Statement introduced in Release 9.3 of JUNOS software.
Specify the static rules to be used as match criteria.
This statement is supported on SRX-series devices.
The remaining statement is explained separately.
For configuration instructions and examples, see the JUNOS Software Security Configuration Guide.
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.