# show | display set
...
set firewall family inet filter FILTER01 term TERM10 from source-address 10.0.0.1/32
set firewall family inet filter FILTER01 term TERM10 from destination-address 192.168.1.0/24
set firewall family inet filter FILTER01 term TERM10 from tcp-established
set firewall family inet filter FILTER01 term TERM10 then accept
set firewall family inet filter FILTER01 term TERM20 then count COUNTER20
set firewall family inet filter FILTER01 term TERM20 then discard
...
単純に以下のターム定義 TERM15 を追加で設定すると
12345
# set firewall family inet filter FILTER01 term TERM15 from source-address 10.0.0.2/32
# set firewall family inet filter FILTER01 term TERM15 from destination-address 192.168.1.0/24
# set firewall family inet filter FILTER01 term TERM15 from protocol tcp
# set firewall family inet filter FILTER01 term TERM15 from destination-port 20-21
# set firewall family inet filter FILTER01 term TERM15 then accept
# show | display set
...
set firewall family inet filter FILTER01 term TERM10 from source-address 10.0.0.1/32
set firewall family inet filter FILTER01 term TERM10 from destination-address 192.168.1.0/24
set firewall family inet filter FILTER01 term TERM10 from tcp-established
set firewall family inet filter FILTER01 term TERM10 then accept
set firewall family inet filter FILTER01 term TERM20 then count COUNTER20
set firewall family inet filter FILTER01 term TERM20 then discard
+ set firewall family inet filter FILTER01 term TERM15 from source-address 10.0.0.2/32+ set firewall family inet filter FILTER01 term TERM15 from destination-address 192.168.1.0/24+ set firewall family inet filter FILTER01 term TERM15 from protocol tcp+ set firewall family inet filter FILTER01 term TERM15 from destination-port 20-21+ set firewall family inet filter FILTER01 term TERM15 then accept...
# delete firewall family inet filter FILTER01 term TERM10
# delete firewall family inet filter FILTER01 term TERM20
#
# set firewall family inet filter FILTER01 term TERM10 from source-address 10.0.0.1/32
# set firewall family inet filter FILTER01 term TERM10 from destination-address 192.168.1.0/24
# set firewall family inet filter FILTER01 term TERM10 from tcp-established
# set firewall family inet filter FILTER01 term TERM10 then accept
# set firewall family inet filter FILTER01 term TERM15 from source-address 10.0.0.2/32
# set firewall family inet filter FILTER01 term TERM15 from destination-address 192.168.1.0/24
# set firewall family inet filter FILTER01 term TERM15 from protocol tcp
# set firewall family inet filter FILTER01 term TERM15 from destination-port 20-21
# set firewall family inet filter FILTER01 term TERM15 then accept
# set firewall family inet filter FILTER01 term TERM20 then count COUNTER20
# set firewall family inet filter FILTER01 term TERM20 then discard
# set firewall family inet filter FILTER01 term TERM15 from source-address 10.0.0.2/32
# set firewall family inet filter FILTER01 term TERM15 from destination-address 192.168.1.0/24
# set firewall family inet filter FILTER01 term TERM15 from protocol tcp
# set firewall family inet filter FILTER01 term TERM15 from destination-port 20-21
# set firewall family inet filter FILTER01 term TERM15 then accept
#
# insert firewall family inet filter FILTER01 term TERM15 after term TERM_10
そうすると、以下のように意図したとおり定義できる。
12345678910111213
# show | display set
...
set firewall family inet filter FILTER01 term TERM10 from source-address 10.0.0.1/32
set firewall family inet filter FILTER01 term TERM10 from destination-address 192.168.1.0/24
set firewall family inet filter FILTER01 term TERM10 from tcp-established
set firewall family inet filter FILTER01 term TERM10 then accept
+ set firewall family inet filter FILTER01 term TERM15 from source-address 10.0.0.2/32+ set firewall family inet filter FILTER01 term TERM15 from destination-address 192.168.1.0/24+ set firewall family inet filter FILTER01 term TERM15 from protocol tcp+ set firewall family inet filter FILTER01 term TERM15 from destination-port 20-21+ set firewall family inet filter FILTER01 term TERM15 then accept set firewall family inet filter FILTER01 term TERM20 then count COUNTER20
set firewall family inet filter FILTER01 term TERM20 then discard