We recommend auditing of various types of security violations, including attempts to access the system from unauthorized locations. JUNOS software allows configuration of firewall filters to detect such attempts and create audit log entries when they occur.
In JUNOS software, management traffic is isolated from other types of traffic, such as user transit traffic, in several ways. JUNOS software maintains a separate virtual address space for every authorized manager. Traffic separation is also accomplished when a separate management network is connected to a dedicated management port (a dedicated management port on J-series platforms or fxp0 on other platforms).
You should deploy firewall filters on management ports to limit access to authorized managers and locations. For more information about firewall filters, see the JUNOS Policy Framework Configuration Guide or J-series Services Router Advanced WAN Access Configuration Guide.
This chapter provides the following information about JUNOS software firewall filters: