system-services (Security Zones Host Inbound Traffic)
Syntax
system-services { (service-name | all <service-name except>); }
Hierarchy Level
[edit security zones security-zone zone-name host-inbound-traffic]
Description
Specify the types of incoming system service traffic that can reach the device for all interfaces in a security zone. By default, a security zone has all system services disabled. You can allow the inbound system services traffic in one of the following ways:
Allow system services individually.
Allow all system services.
Allow all system services with the exception of the specified services.
Options
service-name— | Name of system service traffic that can reach the device.
|
service-name
except — |
(Optional) Allow all inbound service traffic, except the specified service traffic types, to reach the device. In the following example, the configuration allows all system service traffic, with the exception of FTP and HTTP, to reach the device: [edit] user@host# set security zones security-zone trust host-inbound-traffic system-services all user@host# set security zones security-zone trust host-inbound-traffic system-services ftp except user@host# set security zones security-zone trust host-inbound-traffic system-services http except |
Required Privilege Level
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.
Release Information
Statement introduced in Junos OS Release 8.5.