Betr.: [j-nsp] Firewall filter: Allow ISIS

bart.teunis at imtech.nl bart.teunis at imtech.nl
Wed Aug 27 14:41:03 EDT 2003



Neil,

I believe in this example this would be :

term allow-ISIS {
     from {
      source-address {
         192.168.2.0/24;
         192.168.3.0/24;
      }
      protocol iso;
     }
     then accept;
}


By the way : This is basic routing
                                                                           
 Met vriendelijke groet            Imtech Telecom                          
                                   Phone +31 (0)73 640 64 64               
                                   Fax +31 (0)73 640 60 18                 
 Bart Teunis                       Mobiel +31 (0)6 53 70 58 77             
 Network Consultant                www.imtechtele.com                      
                                                                           
                                                                           
 (Embedded image moved to file:                                            
 pic16330.gif)                                                             
                                                                           
                                                                           
                                                                           
                                                                           
 ATTENTION                                                                 
 The information in this                                                   
 electronic mail message is                                                
 private and confidential,                                                 
 and only intended for the                                                 
 addressee.                                                                
 Should you receive this message                                           
 by mistake, we apologise for the                                          
 inconvenience                                                             
 and request you to delete it.                                             
 If you could inform the sender by                                         
 reply transmission that would be                                          
 much                                                                      
 appreciated.                                                              
                                                                           

















|---------+----------------------------------->
|         |           "Neil Stirling"         |
|         |           <neil.stirling at nortelnet|
|         |           works.com>              |
|         |           Verzonden door:         |
|         |           juniper-nsp-bounces at puck|
|         |           .nether.net             |
|         |                                   |
|         |                                   |
|         |           08/27/2003 01:06 PM     |
|         |                                   |
|---------+----------------------------------->
  >------------------------------------------------------------------------------------------------------------|
  |                                                                                                            |
  |        Aan:     juniper-nsp at puck.nether.net                                                                |
  |        cc:                                                                                                 |
  |        Onderwerp:     [j-nsp] Firewall filter: Allow ISIS                                                  |
  >------------------------------------------------------------------------------------------------------------|






All,

I'm being a little lazy, but need to know what parameter 'from' is set for
matching all ISIS packets in a firewall filter.

This is obviously applied to the lo0 interface.

An OSPF example;

term allow-ospf {
     from {
      source-address {
         192.168.2.0/24;
         192.168.3.0/24;
      }
      protocol ospf;
     }
     then accept;
}

There is NO 'protocol isis' or 'iso' in release 6.0R1.3.

Thanks, Neil.

_______________________________________________
juniper-nsp mailing list juniper-nsp at puck.nether.net
http://puck.nether.net/mailman/listinfo/juniper-nsp



-------------- next part --------------
A non-text attachment was scrubbed...
Name: pic16330.gif
Type: image/gif
Size: 506 bytes
Desc: not available
Url : https://puck.nether.net/pipermail/juniper-nsp/attachments/20030827/2d9fa95b/pic16330-0001.gif


More information about the juniper-nsp mailing list