eracl-ip6-match (packet-forwarding-options)
Syntax
eracl-ip6-match { (srcip6-and-destip6 | srcip6-only); } }
Hierarchy Level
[edit system packet-forwarding-options]
Description
Use the options of this command to allow source and/or destination IPv6 address match conditions for eRACL inet6 filters.
In Junos, firewall filters are classified as ingress or egress depending on
where in the sequence the packet is evaluated and action taken. Filtering
IPv6 traffic on an inet6
egress interface can be useful,
for example, for safeguarding a third-party device connected to the
Juniper switch.
After configuring, modifying, or deleting the eracl-ip6-match
statement, you must commit the configuration, and the packet forwarding
engine (PFE) must be restarted.
Options
eracl-ip6-match | Configuring
match conditions in a firewall filter for IPv6 source and/or destination
IP addresses is only allowed if the
|
Required Privilege Level
flow-tap
Release Information
Statement introduced in Junos OS Release 19.1 (EX4300 and QFX5100 Series switches only).