set interfaces vlan unit 100 description guest set interfaces vlan unit 100 family inet filter input guest-to-internet-only set interfaces vlan unit 100 family inet filter output no-corp-to-guest set interfaces vlan unit 100 family inet address 192.168.1.254/24 set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 10.0.0.0/8 set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 172.16.0.0/12 set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 192.168.0.0/16 set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 127.0.0.0/8 set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 169.254.0.0/16 set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 224.0.0.0/3 set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 then discard set firewall family inet filter guest-to-internet-only term allow-everything-else then accept set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 10.0.0.0/8 set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 172.16.0.0/12 set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 192.168.0.0/16 set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 127.0.0.0/8 set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 169.254.0.0/16 set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 224.0.0.0/3 set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 then discard set firewall family inet filter no-corp-to-guest term allow-everything-else then accept
↧
Re: Guest internet firewall filter
↧