Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Routing Policy and Firewall Filters

  • Support for increasing firewall filter scale (PTX10001-36MR, PTX10004, PTX10008, and PTX10016)—Starting in Junos OS Evolved Release 24.2R1, we support two new configuration statements—scale-mode and no-incremental-update. Use scale-mode to accommodate more firewall filter terms, when you're focused more on scale than on performance. Use no-incremental-update to prevent the firewall filter from undergoing incremental update; the filter undergoes make-before-break (MBB).

    [See scale-mode and no-incremental-update.]

  • Transient firewall filter for out of resource avoidance (PTX10001-36MR, PTX10003, PTX10004, PTX10008, and PTX10016)—Starting in Junos OS Evolved Release 24.2R1, you can configure a transient firewall filter with a presumably smaller memory footprint that performs the role of an interim firewall when its parent firewall filter is being modified.

    [See transient-filter.]

  • Support for matching IPv6 flow label field (PTX10008)—Starting in Junos OS Evolved Release 24.2R1, support is added for matching the 20-bit flow-label field in the header of an IPv6 packet. We've added two new match conditions for this feature—flow-label flow label value and flow-label flow label value mask mask value.

    [See Firewall Filter Match Conditions for IPv6 Traffic.]