Restrict Traffic with ACLs on Juniper aka (Firewall Filters)
HTML-код
- Опубликовано: 5 окт 2024
- Learn how to block and accept specific traffic based on protocols and address using firewall filters on Juniper devices.
Below is a link to Juniper's official documentation for information on how to configure firewall filters on Junos.
www.juniper.ne...
Note: On some versions of Junos you may need to specify the filter under the family hierarchy in order for the filter to be referenced properly: "edit firewall family filter inet"
See Juniper's documentation for more information on how to further configure firewall filters (acls) on Junos:
www.juniper.net/documentation/us/en/software/junos/routing-policy/topics/concept/firewall-filter-stateless-guidelines-for-configuring.html
Good videos and straight to the point.
Much appreciated
Nice video.... Going to renew my JNCIA soon and this topic was always challenging.
You've got this!
What about for allowing certain network protocols? For example, a network scan that uses port 8834
Yes, firewall filters will allow you to restrict specific TCP/UDP ports aswell
will this work for juniper ex 4300 and 2200 swiches as well ?
Hi, and yes. Firewall filters (aka ACLs) are built into all Junos devices.
great guide. thanks
Hi please tutor VLAN juniper srx
VLAN configuration is pretty standard across the different Juno’s devices. However there’s a slight difference between the routing and switching platforms. Heres a video I put together explaining the differences:
ruclips.net/user/shorts0RpuvGVVV-o?feature=share
Hi, my sw output the next messsage " Referenced filter 'PRUEBA' is not defined"
set firewall filter PRUEBA term 1 from source-address 172.16.100.21
set firewall filter PRUEBA term 1 from protocol icmp
set firewall filter PRUEBA term 1 then reject
set firewall filter PRUEBA term 2 then accept
set interface ge-0/0/1.0 family inet filter input PRUEBA
commit
[edit interfaces ge-0/0/1 unit 0 family inet]
'filter'
Referenced filter 'PRUEBA' is not defined
error: Failed to read config
commit-check failed
commit-check failed
error: configuration check-out failed
@@BrandonImperia Hi Brandon, your config looks correct. However I should note on some versions of Junos you may need to specify the filter under the family hierarchy in order for the filter to be referenced properly: "edit firewall family filter inet"