To configure a firewall filter, you must perform at least the following tasks:
- Configure firewall filters—To configure firewall filters, include the
familyfamily-namestatement and one or morefilterstatements at the[edit firewall]hierarchy level:[edit firewall]familyfamily-name{filterfilter-name{termterm-name{from {match-conditions;}then {action;action-modifiers;}}}}Apply firewall filters to interfaces—Firewall filters control local packets to and from the Routing Engine if they are applied to the loopback interface, lo0. With the Internet Processor II application-specific integrated circuit (ASIC), firewall filters can control data packets through the routing platform when they are applied to an external interface. To have a firewall filter take effect, you must apply it to an interface by including thefilterstatement at the[edit interfacesinterface-nameunitlogical-unit-numberfamilyfamily-name]hierarchy level:[edit interfacesinterface-nameunitlogical-unit-numberfamilyfamily-name]filter {inputfilter-name;outputfilter-name;}