Mailing List Archive

IS-IS/OSI filtering
Is there a way to match IS-IS/OSI packets in a firewall term, or are they
even matched at all? There doesn't seem to be a term under "from
protocol", and they don't seem to show up in a default term (no from)
count or log...

--
Richard A Steenbergen <ras@e-gerbil.net> http://www.e-gerbil.net/ras
GPG Key ID: 0xF8B12CBC (7535 7F59 8204 ED1F CC1C 53AF 4C41 5ECA F8B1 2CBC)
IS-IS/OSI filtering [ In reply to ]
AFAIK only binary on/off type filtering is supported, that is if you do not enable "family iso" in a unit then iso is filtered.. After all, family iso is only supported for IS-IS on Juniper so the argument for this was that there shouldn't be any need for more detailed iso-filtering?

///Markus

-----Original Message-----
From: juniper-nsp-bounces@puck.nether.net
[mailto:juniper-nsp-bounces@puck.nether.net]On Behalf Of Richard A
Steenbergen
Sent: 22. helmikuuta 2004 20:44
To: juniper-nsp@puck.nether.net
Subject: [j-nsp] IS-IS/OSI filtering


Is there a way to match IS-IS/OSI packets in a firewall term, or are they
even matched at all? There doesn't seem to be a term under "from
protocol", and they don't seem to show up in a default term (no from)
count or log...

--
Richard A Steenbergen <ras@e-gerbil.net> http://www.e-gerbil.net/ras
GPG Key ID: 0xF8B12CBC (7535 7F59 8204 ED1F CC1C 53AF 4C41 5ECA F8B1 2CBC)
_______________________________________________
juniper-nsp mailing list juniper-nsp@puck.nether.net
http://puck.nether.net/mailman/listinfo/juniper-nsp

This communication is confidential and intended solely for the addressee(s). Any unauthorized review, use, disclosure or distribution is prohibited. If you believe this message has been sent to you in error, please notify the sender by replying to this transmission and delete the message without disclosing it. Thank you.

E-mail including attachments is susceptible to data corruption, interruption, unauthorized amendment, tampering and viruses, and we only send and receive e-mails on the basis that we are not liable for any such corruption, interception, amendment, tampering or viruses or any consequences thereof.
IS-IS/OSI filtering [ In reply to ]
Richard,

Firewall filters can be used to match IPv4, IPv6, and MPLS traffic:

http://www.juniper.net/techpubs/software/junos/junos62/swconfig62-
policy/html/firewall-overview.html

Sorry, no ISIS/OSI option there.

Scott

On Sun, 22 Feb 2004 13:43:36 -0500, Richard A Steenbergen wrote
> Is there a way to match IS-IS/OSI packets in a firewall term, or are
> they even matched at all? There doesn't seem to be a term under
> "from protocol", and they don't seem to show up in a default term
> (no from) count or log...