fast-lookup-filter (PTX)
Syntax
fast-lookup-filter
Hierarchy Level
[edit firewall family family-name filter output filter-name], [edit logical-systems logical-system-name firewall family family-name filter output filter-name]
Description
On PTX platforms, the fast-lookup-filter
(FFT) is available on
Inet, Inet 6, Ethernet-Switching, Any, MPLS (no MPLS label
match support) and CCC firewall filter families. Using
fast-lookup-filter
on output filters prioritizes the
filters for fast processing. Applying the
fast-lookup-filter
configuration on output firewall
filters, programs the firewall filters on the fast-lookup-filter block on
the device, to enable high-speed line-rate (2 billion packets-per-second)
processing of the firewall filters in the egress direction.
On PTX platforms, only the following firewall filter match conditions and actions are supported for fast look filters.
CLI |
IPv6 |
IPv4 |
MPLS |
Ethernet switching |
Any |
CCC |
Except match |
---|---|---|---|---|---|---|---|
learn-vlan-id |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
vlan-id |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
ttl |
Yes |
Yes |
No |
No |
No |
No |
Yes |
source-port |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
destination-port |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
source-class |
Yes |
Yes |
No |
No |
No |
Yes |
Yes |
interface-group |
No |
No |
No |
No |
No |
No |
Yes |
forwarding-class |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
loss-priority |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
interface |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
destination-mac |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
source-mac |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
outer-vlan |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
inner-vlan |
No |
No |
No |
Yes |
Yes |
Yes |
Yes |
ether-type |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
source-address |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
source-prefix-list |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
destination-address |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
destination-prefix-list |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
Yes |
dscp |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
Is-fragment |
Yes |
No |
NA |
Yes |
Yes |
Yes |
Yes |
Ip-options |
Yes |
Yes |
NA |
No |
No |
No |
Yes |
protocol |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
src-port |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
dst-port |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
icmp-type |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
icmp-code |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
tcp-flags |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
tcp-initial |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
tcp-established |
Yes |
Yes |
NA |
Yes |
Yes |
Yes |
Yes |
gre-key |
No |
No |
NA |
NA |
NA |
NA |
Yes |
vxlan-header |
No |
No |
NA |
NA |
NA |
NA |
Yes |
CLI |
Supported? |
---|---|
accept |
Yes |
discard |
Yes |
reject |
Yes |
count |
Yes |
forwarding-class |
Yes |
traffic-class |
No |
loss-priority |
Yes |
policer |
Yes |
sample |
Yes |
syslog |
Yes |
-
Only 8 unique firewall filters per PFE are supported across all supported firewall filter families.
-
Fast lookup is applicable only for output filters.
-
Unsupported firewall filter matches and actions is processed from the default processing pipeline, and not programmed on the fast-lookup-filter block.
-
Fast lookup filters are limited to 4096 rules of 96 bits or 2048 rules of 192 bits or 1024 rules of 384 bits.
-
Maximum 256 logical interface (IFL) bindings for interface specific filter per PFE.
-
The
fast-lookup-filter
configuration cannot be applied on input filters. -
There is no support for split filter or filter chaining.
-
The
fast-lookup-filter
configuration cannot be used to prioritize amongst the 8 unique fast lookup filters. -
Fast lookup filters do not support slow counters. Counter scale is limited to 48 thousand counter per PFE (Packet Forwarding Engine).
Required Privilege Level
firewall—To view this statement in the configuration.
firewall-control—To add this statement to the configuration.
Release Information
Statement introduced in Junos OS Evolved 23.1 R1 for PTX platforms.