Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation

Statement Hierarchy for Configuring a Filter to Match on a Set of Interface Groups

You can configure a standard stateless firewall filter or a service filter term that matches packets tagged for a specified interface group or set of interface groups.

To configure a standard stateless firewall filter that matches packets tagged for a specified interface group or set of interface groups, configure a filter term that uses the interface-group interface-group-number match condition:

firewall {family (inet | inet6 | vpls | ccc | bridge) {filter filter-name {term term-name {from {interface-group interface-group-number;}then {filter-actions;}}}}}

To configure a service filter that matches packets tagged for a specified interface group or set of interface groups, configure a filter term that uses the interface-group interface-group-name match condition:

firewall {family (inet | inet6) {service-filter filter-name {term term-name {from {interface-group interface-group-number;}then {service-filter-actions;}}}}}

You can configure the firewall filter at one of the following hierarchy levels:

  • [edit]
  • [edit logical-systems logical-system-name]

Published: 2013-04-10