Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

Firewall Filters

More Information:

Firewall Filters

Firewall filters provide rules that define whether to permit or deny packets that are transiting a port on a Junos device from a source endpoint to a destination endpoint. You configure firewall filters to determine whether to permit or deny traffic before it enters or exits a port to which the firewall filter is applied. To apply a firewall filter, you must first configure the filter and then apply it to a port, either while manually configuring a port or through port profiles.
Feature hierarchy Feature Name
Firewall Filters / Filter Instantiation: Interface-specific
Firewall Filters / Filter Instantiation: Logical Interface
Firewall Filters / Firewall Filters
Firewall Filters / Firewall filter features
Firewall Filters / Firewall filters and policers: Abstracted fabric interface
Firewall Filters / Firewall filters: 6-tuple lookup in inner GTP encapsulated packet
Firewall Filters / Firewall filters: ARP policers
Firewall Filters / Firewall filters: CoS
Firewall Filters / Firewall filters: Discard (dsc) interface: Family inet
Firewall Filters / Firewall filters: Discard (dsc) interface: Family inet6
Firewall Filters / Firewall filters: Display version information
Firewall Filters / Firewall filters: Dynamic allocation of TCAM memory
Firewall Filters / Firewall filters: ECMP operation on MPLS
Firewall Filters / Firewall filters: EVPN-VXLAN with IPv6 underlays
Firewall Filters / Firewall filters: Enhancement for better resource optimization
Firewall Filters / Firewall filters: Family ccc/any
Firewall Filters / Firewall filters: Family inet
Firewall Filters / Firewall filters: Family inet6
Firewall Filters / Firewall filters: Fine control over classification of CPU generated packets
Firewall Filters / Firewall filters: Flexible match conditions
Firewall Filters / Firewall filters: Force premium for the Bridge, CCC, and VPLS families
Firewall Filters / Firewall filters: Forwarding table filter
Firewall Filters / Firewall filters: Hardware-assisted segmented filters for large filters
Firewall Filters / Firewall filters: IFL: family inet
Firewall Filters / Firewall filters: IFL: family inet6
Firewall Filters / Firewall filters: IFL: family mpls
Firewall Filters / Firewall filters: IPv4 and IPv6: Layer 3 gateways in EVPN-VXLAN fabrics
Firewall Filters / Firewall filters: IPv6
Firewall Filters / Firewall filters: IPv6 prefix
Firewall Filters / Firewall filters: Input-list and output-list
Firewall Filters / Firewall filters: Input/output filter for flexible tunnel interface
Firewall Filters / Firewall filters: Input/output filters for IRB
Firewall Filters / Firewall filters: LAGs
Firewall Filters / Firewall filters: Layer 2 VPNs: IEEE 802.1p priority match conditions
Firewall Filters / Firewall filters: Layer 2 egress filtering: EVPN-VXLAN interfaces
Firewall Filters / Firewall filters: Layer 2 firewall filter families: Inline monitoring services
Firewall Filters / Firewall filters: Layer 2: Match conditions
Firewall Filters / Firewall filters: Logical systems
Firewall Filters / Firewall filters: Loopback interface
Firewall Filters / Firewall filters: Management interface
Firewall Filters / Firewall filters: Match condition prefix-list for the protocol family VPLS
Firewall Filters / Firewall filters: Micro segmentation on VLANs and VXLANs
Firewall Filters / Firewall filters: Network slicing
Firewall Filters / Firewall filters: Non-zero DSCP values
Firewall Filters / Firewall filters: Policer action as forwarding-class and loss priority (PLP)
Firewall Filters / Firewall filters: SCTP traffic
Firewall Filters / Firewall filters: SRv6
Firewall Filters / Firewall filters: Transient filter
Firewall Filters / Firewall filters: View a CLI and non-CLI configured and/or compiled information
Firewall Filters / Firewall filters: Virtual management interface
Firewall Filters / Host protection
Firewall Filters / Ingress policy enforcement and tag propagation
Firewall Filters / Ingress port and VLAN firewall filters: IPv6
Firewall Filters / Interfaces that use the same filter list to use a common template
Firewall Filters / Layer 2 frame filtering
Firewall Filters / Loopback firewall filter scale optimization
Firewall Filters / MPLS firewall filter support on loopback interface
Firewall Filters / Multiple tag protocol identifiers (TPIDs), accounting, and filtering
Firewall Filters / Next-filter as a firewall filter action
Firewall Filters / OpenConfig: Firewall filter configuration
Firewall Filters / Optimize TCAM when EVPN/VXLAN is enabled
Firewall Filters / Optimized performance for DSCP and traffic-class firewall filter match conditions
Firewall Filters / Output filter actions to set DSCP / Traffic Class and Forwarding Class on the loopback interface
Firewall Filters / Packet Filtering
Firewall Filters / Per-group TCAM utilization telemetry, CLI, and syslog
Firewall Filters / Policer mark down action
Firewall Filters / Port firewall filters (egress)
Firewall Filters / Port firewall filters (ingress)
Firewall Filters / Port-mirroring firewall filter: CCC, bridge, and VPLS
Firewall Filters / Profiles to improve the firewall filter scale
Firewall Filters / Removal of input-list and output-list statements for firewall filters for the ccc and mpls protocol families applied to loopback, internal Ethernet, and USB modem interfaces
Firewall Filters / Routed firewall filters (egress)
Firewall Filters / Routed firewall filters (ingress)
Firewall Filters / Simple Filter
Firewall Filters / Single-rate two-color marking
Firewall Filters / Source and destination port range optimize
Firewall Filters / Source checking for forwarding filter tables
Firewall Filters / Source class-based firewall filter actions
Firewall Filters / Standard Firewall Filter Match Conditions for MPLS Traffic
Firewall Filters / Stateful firewall chaining for FTP, TFTP, and RTSP data sessions
Firewall Filters / TCP/UDP port ranges in classification
Firewall Filters / Using a firewall filter to prevent or allow datagram fragmentation
Firewall Filters / VLAN firewall filters (2K egress)
Firewall Filters / VLAN firewall filters (egress)
Firewall Filters / VLAN firewall filters (ingress)
Firewall Filters / gRPC streaming for Junos Telemetry Interface firewall filter statistics
Firewall Filters / shmlog for CoS and firewall filter plug-ins
Firewall Filters / Fast lookup firewall filters / FLT: Origin and neighbor autonomous systems
Firewall Filters / Fast lookup firewall filters / Fast lookup filter attachment: Family inet under logical interface, output
Firewall Filters / Fast lookup firewall filters / Fast lookup filter attachment: Family inet6 under logical interface, output
Firewall Filters / Fast lookup firewall filters / Fast lookup filter attachment: Family mpls under logical interface, output
Firewall Filters / Fast lookup firewall filters / Fast lookup filters (FLT)
Firewall Filters / Fast lookup firewall filters / Fast lookup filters for BGP FlowSpec routes
Firewall Filters / Firewall filter actions / Destination class-based firewall filter actions
Firewall Filters / Firewall filter actions / Enhancements to support log and syslog firewall filter actions
Firewall Filters / Firewall filter actions / Filter Action: count
Firewall Filters / Firewall filter actions / Filter Action: forwarding-class
Firewall Filters / Firewall filter actions / Filter Action: next-intf
Firewall Filters / Firewall filter actions / Filter Action: next-ip
Firewall Filters / Firewall filter actions / Filter Action: next-ip6
Firewall Filters / Firewall filter actions / Filter Action: permit, drop, police
Firewall Filters / Firewall filter actions / Filter Action: reject
Firewall Filters / Firewall filter actions / Filter Action: syslog
Firewall Filters / Firewall filter actions / Filter action: De-encapsulate IP-in-IP in input filter
Firewall Filters / Firewall filter actions / Filter action: De-encapsulation (GRE)
Firewall Filters / Firewall filter actions / Filter action: De-encapsulation (GRE): Forwarding class
Firewall Filters / Firewall filter actions / Filter action: De-encapsulation (GRE): Routing instance option with IPv4/v6 Address
Firewall Filters / Firewall filter actions / Filter action: De-encapsulation (GRE): Sampling
Firewall Filters / Firewall filter actions / Filter action: De-encapsulation: GRE
Firewall Filters / Firewall filter actions / Filter action: De-encapsulation: IPv4 and IPv6 unicast IP-over-IP (IPv4)
Firewall Filters / Firewall filter actions / Filter action: De-encapsulation: IPv4 and IPv6 unicast traffic encapsulated in IPv4 IP-in-IP tunnels
Firewall Filters / Firewall filter actions / Filter action: Discard
Firewall Filters / Firewall filter actions / Filter action: Encapsulate GRE in input filter
Firewall Filters / Firewall filter actions / Filter action: Filter (nested filter)
Firewall Filters / Firewall filter actions / Filter action: IPv4/v6 decapsulate (IP-IP)
Firewall Filters / Firewall filter actions / Filter action: Logging, syslog, reject
Firewall Filters / Firewall filter actions / Filter action: Loss-priority (PLP)
Firewall Filters / Firewall filter actions / Filter action: Port Mirror
Firewall Filters / Firewall filter actions / Filter action: Remote port mirroring and analyzer
Firewall Filters / Firewall filter actions / Filter action: Set forwarding class (input filter only)
Firewall Filters / Firewall filter actions / Filter action: Tunnel de-encapsulation, IPv4 and IPv6, with no-decrement-ttl
Firewall Filters / Firewall filter actions / Filter action: policer
Firewall Filters / Firewall filter actions / Firewall action: vlan
Firewall Filters / Firewall filter actions / Firewall filter action is counters
Firewall Filters / Firewall filter actions / Firewall filter action is logging, syslog, reject
Firewall Filters / Firewall filter actions / Firewall filter action is mirroring to an interface
Firewall Filters / Firewall filter actions / Firewall filter action is permit, drop, police, mark
Firewall Filters / Firewall filter actions / Firewall filter action: Redirect to inline monitoring instance
Firewall Filters / Firewall filter attachments / Filter attachment: Discard interface (dsc), output: Family inet
Firewall Filters / Firewall filter attachments / Filter attachment: Discard interface (dsc), output: family inet6
Firewall Filters / Firewall filter attachments / Filter attachment: Family any under logical interface, input
Firewall Filters / Firewall filter attachments / Filter attachment: Family any under logical interface, output
Firewall Filters / Firewall filter attachments / Filter attachment: Family ccc under logical interface, input
Firewall Filters / Firewall filter attachments / Filter attachment: Family ccc under logical interface, output
Firewall Filters / Firewall filter attachments / Filter attachment: Family inet6 under logical interface, input
Firewall Filters / Firewall filter attachments / Filter attachment: Family inet6 under logical interface, output
Firewall Filters / Firewall filter attachments / Filter attachment: IRB: Interface for EVPN-VXLAN virtual gateway, input
Firewall Filters / Firewall filter attachments / Filter attachment: Input filter chains
Firewall Filters / Firewall filter attachments / Filter attachment: Output filter chains
Firewall Filters / Firewall filter match conditions / 20-bit flow-label field matching
Firewall Filters / Firewall filter match conditions / Additional numeric-range match conditions in firewall filters
Firewall Filters / Firewall filter match conditions / DSCP and Traffic Class firewall filter match conditions on the loopback interface
Firewall Filters / Firewall filter match conditions / Filter Match: DSCP and Forwarding Class at Loopback Interface
Firewall Filters / Firewall filter match conditions / Filter match: Any IP options (ip-options any)
Firewall Filters / Firewall filter match conditions / Filter match: Destination MAC address
Firewall Filters / Firewall filter match conditions / Filter match: Flexible Offset
Firewall Filters / Firewall filter match conditions / Filter match: GRE-key
Firewall Filters / Firewall filter match conditions / Filter match: IPv6 hop-limit
Firewall Filters / Firewall filter match conditions / Filter match: IPv6 next-header
Firewall Filters / Firewall filter match conditions / Filter match: Interfaces
Firewall Filters / Firewall filter match conditions / Filter match: MPLS: Header metadata: forwarding-class, loss-priority
Firewall Filters / Firewall filter match conditions / Filter match: MPLS: IPv4/IPv6 Payload
Firewall Filters / Firewall filter match conditions / Filter match: Packet Length
Firewall Filters / Firewall filter match conditions / Filter match: TCP/UDP port ranges
Firewall Filters / Firewall filter match conditions / Filter match: Tcp-flags: Bitwise operations: and
Firewall Filters / Firewall filter match conditions / Filter match: Tcp-flags: Logical operations: and
Firewall Filters / Firewall filter match conditions / Filter match: Tcp-flags: Logical operations: negate
Firewall Filters / Firewall filter match conditions / Filter match: Tcp-flags: Logical operations: or
Firewall Filters / Firewall filter match conditions / Filter match: first fragment
Firewall Filters / Firewall filter match conditions / Filter match: tcp-flags
Firewall Filters / Firewall filter match conditions / Filter match: tcp-flags: bitwise operations: negate
Firewall Filters / Firewall filter match conditions / Filter match: tcp-flags: bitwise operations: or
Firewall Filters / Firewall filter match conditions / Firewall family bridge match criteria for IPv6
Firewall Filters / Firewall filter match conditions / Firewall feature matching on gre-key
Firewall Filters / Firewall filter match conditions / Firewall filter match condition is Hop-Limit
Firewall Filters / Firewall filter match conditions / Firewall filter match condition support for IPv6 extension headers
Firewall Filters / Firewall filter match conditions / Firewall filter match condition support for additional ICMPv6 types
Firewall Filters / Firewall filter match conditions / Firewall filter match conditions based on IEEE 802.1p VLAN priority bits
Firewall Filters / Firewall filter match conditions / Firewall filter match conditions for Layer 2 bridging and VPLS
Firewall Filters / Firewall filter match conditions / Five tuple match conditions
Firewall Filters / Firewall filter match conditions / IPv6 filter: Fragmented packets
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match ICMP values
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match IPv6 packet length
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match TCP flags
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match Traffic Class field
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match destination address
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match destination address - Flow
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match destination port
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match destination port - Flow
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match source address
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match source address - Flow
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match source port
Firewall Filters / Firewall filter match conditions / IPv6 filter: Match source port - Flow
Firewall Filters / Firewall filter match conditions / Match - MPLS Header - Bottom of Stack
Firewall Filters / Firewall filter match conditions / Match - MPLS Header - EXP
Firewall Filters / Firewall filter match conditions / Match - MPLS Header - Label
Firewall Filters / Firewall filter match conditions / Match - MPLS Header - TTL
Firewall Filters / Firewall filter match conditions / Match: Destination Class and Source Class
Firewall Filters / Firewall filter match conditions / Match: Hop-Limit
Firewall Filters / Firewall filter match conditions / Match: IPv4 and IPv6
Firewall Filters / Firewall filter match conditions / Match: Interface Group
Firewall Filters / Firewall filter match conditions / Match: L4 ports
Firewall Filters / Firewall filter match conditions / Match: MAC Address
Firewall Filters / Firewall filter match conditions / Match: Protocol
Firewall Filters / Firewall filter match conditions / Match: Source or destination ports in named list
Firewall Filters / Firewall filter match conditions / Match: isFragment
Firewall Filters / Firewall filter match conditions / Match: next-header (IPv6)
Firewall Filters / Firewall filter match conditions / Match: payload-protocol (IPv6)
Firewall Filters / Firewall filter match conditions / Matching IPv6 source addresses from an inet6 egress interface
Firewall Filters / Firewall filter match conditions / Multifield ingress queuing classifier filter