Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

fast-lookup-filter (PTX)

Syntax

Hierarchy Level

Description

On PTX platforms, the fast-lookup-filter (FFT) is available on Inet, Inet 6, Ethernet-Switching, Any, MPLS (no MPLS label match support) and CCC firewall filter families. Using fast-lookup-filter on output filters prioritizes the filters for fast processing. Applying the fast-lookup-filter configuration on output firewall filters, programs the firewall filters on the fast-lookup-filter block on the device, to enable high-speed line-rate (2 billion packets-per-second) processing of the firewall filters in the egress direction.

On PTX platforms, only the following firewall filter match conditions and actions are supported for fast look filters.

Table 1: Supported firewall filter match conditions for fast lookup filters on PTX platforms

CLI

IPv6

IPv4

MPLS

Ethernet switching

Any

CCC

Except match

learn-vlan-id

No

No

No

Yes

Yes

Yes

Yes

vlan-id

No

No

No

Yes

Yes

Yes

Yes

ttl

Yes

Yes

No

No

No

No

Yes

source-port

Yes

Yes

No

Yes

Yes

Yes

Yes

destination-port

Yes

Yes

No

Yes

Yes

Yes

Yes

source-class

Yes

Yes

No

No

No

Yes

Yes

interface-group

No

No

No

No

No

No

Yes

forwarding-class

Yes

Yes

Yes

Yes

Yes

Yes

Yes

loss-priority

Yes

Yes

Yes

Yes

Yes

Yes

Yes

interface

Yes

Yes

No

Yes

Yes

Yes

Yes

destination-mac

No

No

No

Yes

Yes

Yes

Yes

source-mac

No

No

No

Yes

Yes

Yes

Yes

outer-vlan

No

No

No

Yes

Yes

Yes

Yes

inner-vlan

No

No

No

Yes

Yes

Yes

Yes

ether-type

Yes

Yes

No

Yes

Yes

Yes

Yes

source-address

Yes

Yes

No

Yes

Yes

Yes

Yes

source-prefix-list

Yes

Yes

No

Yes

Yes

Yes

Yes

destination-address

Yes

Yes

No

Yes

Yes

Yes

Yes

destination-prefix-list

Yes

Yes

No

Yes

Yes

Yes

Yes

dscp

Yes

Yes

NA

Yes

Yes

Yes

Yes

Is-fragment

Yes

No

NA

Yes

Yes

Yes

Yes

Ip-options

Yes

Yes

NA

No

No

No

Yes

protocol

Yes

Yes

NA

Yes

Yes

Yes

Yes

src-port

Yes

Yes

NA

Yes

Yes

Yes

Yes

dst-port

Yes

Yes

NA

Yes

Yes

Yes

Yes

icmp-type

Yes

Yes

NA

Yes

Yes

Yes

Yes

icmp-code

Yes

Yes

NA

Yes

Yes

Yes

Yes

tcp-flags

Yes

Yes

NA

Yes

Yes

Yes

Yes

tcp-initial

Yes

Yes

NA

Yes

Yes

Yes

Yes

tcp-established

Yes

Yes

NA

Yes

Yes

Yes

Yes

gre-key

No

No

NA

NA

NA

NA

Yes

vxlan-header

No

No

NA

NA

NA

NA

Yes

Table 2: Supported firewall filter actions for fast lookup filters on PTX platforms

CLI

Supported?

accept

Yes

discard

Yes

reject

Yes

count

Yes

forwarding-class

Yes

traffic-class

No

loss-priority

Yes

policer

Yes

sample

Yes

syslog

Yes

Note:
  • Only 8 unique firewall filters per PFE are supported across all supported firewall filter families.

  • Fast lookup is applicable only for output filters.

  • Unsupported firewall filter matches and actions is processed from the default processing pipeline, and not programmed on the fast-lookup-filter block.

  • Fast lookup filters are limited to 4096 rules of 96 bits or 2048 rules of 192 bits or 1024 rules of 384 bits.

  • Maximum 256 logical interface (IFL) bindings for interface specific filter per PFE.

  • The fast-lookup-filter configuration cannot be applied on input filters.

  • There is no support for split filter or filter chaining.

  • The fast-lookup-filter configuration cannot be used to prioritize amongst the 8 unique fast lookup filters.

  • Fast lookup filters do not support slow counters. Counter scale is limited to 48 thousand counter per PFE (Packet Forwarding Engine).

Required Privilege Level

firewall—To view this statement in the configuration.

firewall-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Evolved 23.1 R1 for PTX platforms.