Defining a network-to-network filter
The following example shows how to define a network-to-network packet filter, allowing packets originating from 10.10.40.0/24 and destined for 172.16.0.0/24. It then applies the firewall instance to packets inbound through the 40 virtual interface (vif 40) and the dp0p1p2 interface.
To create a network-to-network filter, perform the following steps in configuration mode.
Step | Command |
---|---|
Create the configuration node for the FWTEST-4 firewall instance and its rule 1. This rule accepts traffic matching the specified criteria. |
|
Define a rule that filters traffic coming from the 10.10.40.0/24 network. |
|
Define a rule that filters traffic destined for the 172.16.0.0/24 network. |
|
Apply FWTEST-4 to packets bound for this router arriving through vif 40 on dp0p1p2. |
|
Commit the configuration. |
|
Show the configuration. |
|