A primary goal of a typical stateless firewall filter is to protect the Routing Engine processes and resources from malicious or untrusted packets. You can configure a firewall filter like the sample filter protect-RE to restrict traffic destined for the Routing Engine based on its source, protocol, and application. In addition, you can limit the traffic rate of packets destined for the Routing Engine to protect against flood, or denial-of-service (DoS), attacks.
For details, see Configuring a Routing Engine Firewall Filter for Services and Protocols from Trusted Sources and Configuring a Routing Engine Firewall Filter to Protect Against TCP and ICMP Floods.