eracl-profile (packet-forwarding-options)
Syntax
eracl-profile { eracl-scale; }
Hierarchy Level
[edit system packet-forwarding-options firewall] [edit system packet-forwarding-options firewall eracl-profile eracl-scale]
Description
Use the option of this command to configure egress firewall filters, also known as eRACLs, in scaled mode. This feature is supported only in the egress direction (routed traffic exiting the device).
In Junos, firewall filters are classified as ingress or egress depending on where in the sequence the packet is evaluated and action taken. Filtering traffic on an egress interface can be useful, for example, for safeguarding a third-party device connected to the Juniper switch.
Options
eracl-scale | Use this option to increase the number of egress firewall filters to 2000. When you configure an egress filter in scaled mode, the switch uses ingress TCAM space (IFP) to achieve the higher scale. Note:
After configuring, modifying, or deleting the When you enable
|
Required Privilege Level
firewall—To view this statement in the configuration.
firewall-control—To add this statement to the configuration.
Release Information
Statement introduced in Junos OS Evolved Release 19.4R2 (QFX5220 switches).