Routing Policy and Firewall Filters
-
Support for profile categories (ACX7100-32C, ACX7100-48L, ACX7332, ACX7348, ACX7509, and ACX7024)—Profile categories are a way to distinguish firewall filters based on the direction and interface type. The profile categories are namely,
ingress-inet6-user-acl
,ingress-inet6-lo0-acl
, andegress-inet6-user-acl
.[See Overview of Firewall Filter Profiles on ACX Series Routers (Junos OS Evolved).]
- Support for firewall filters (ACX7100-32C, ACX7100-48L, ACX7024,
ACX7024X, ACX7332, ACX7348, and ACX7509)– Support for firewall filters on PFE for
services, such as bridge, IPv4, IPv6, CCC, MPLS and so on, based on packet match conditions
and actions on ACX series devices.
You can enable firewall filters on ACX series routers to monitor and control the traffic transiting the router or destined for the routing engine. The types of filters supported are as follows:
- Interface-specific Filter—Unique firewall filter instance per logical interface for both ingress and egress traffic stream and for all protocol families.
- Physical-interface Filter—Unique firewall filter instance per physical interface applicable only for ethernet-switching, circuit cross-connect (CCC), inet, and inet6 family for ingress traffic.
- Global Filter—Unique firewall filter instance applied globally at PFE level applicable only for ethernet-switching, circuit cross-connect (CCC), inet, and inet6 family for ingress traffic.
[See Firewall Filters Overview. ]