Routing Policy and Firewall Filters
-
Support for firewall filters per logical interface (QFX5110, QFX5120-32C, QFX5120-48T, QFX5120-48Y, QFX5120-48YM, QFX5200, and QFX5210)— Starting in Junos OS Release 22.2R1, you can configure port firewall filters per logical interface, in the input direction, using the service provider-style configuration. To configure, use the
set chassis per-logical-interface-firewallCLI command. In earlier Junos OS releases, port firewall filters would be applied to all logical interfaces of a physical interface. -
Optimize TCAM when EVPN/VXLAN is enabled (EX4400-48F, EX4650, QFX5110, QFX5120-32C, QFX5120-48T, QFX5120-48Y, QFX5120-48YM, QFX5200, and QFX5210)—
In Junos OS Release 22.2R1, we've introduced CLI configuration commands to optimize ternary content addressable memory (TCAM) space usage. Use these commands to prevent ingress filter processor (IFP) TCAM space exhaustion:
set chassis ivacl-firewall-no-portrange-profileset chassis iracl-firewall-ipv4-profileset chassis ipvacl-firewall-l2-profileset chassis input-firewall-optimized-profile