Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


forwarding-options (Security)



Hierarchy Level

Release Information

Statement introduced in Junos OS Release 8.5.

secure-wire option introduced in Junos OS Release 19.3R1.

mode option introduced in Junos OS Release 20.1R1.


Determine how the inet6, iso, and mpls protocol families manage security forwarding options.

  • Packet-based processing is not supported on the following SRX Series devices: SRX5400, SRX5600, and SRX5800.

  • On SRX Series devices, the default mode for processing traffic is flow mode. You can configure SRX Series devices to operate in packet mode to process MPLS packets.

    To configure the packet mode on SRX Series device, use the following command:

    user@host# set security forwarding-options family mpls mode packet-based

    Selective stateless packet-based services allows you to configure the device to provide only packet-based processing for selected traffic based on input filter terms.


modeSpecify TAP mode.
inspect-pass-through-tunnelSpecify TAP mode to inspect pass through IP-IP or GRE tunnel.
interfaceSpecify TAP mode interface name. You can configure up to eight TAP interfaces.
secure-wireSpecify a name for the secure wire interface mapping.
interface-name-1 interface-name-2Specify a pair of peer logical interfaces that constitutes the secure wire mapping.

The remaining statements are explained separately. See CLI Explorer.

Required Privilege Level

security—To view this statement in the configuration.

security-control—To add this statement to the configuration.