[j-nsp] Routing Engine Protection

"Rolf Hanßen" nsp at rhanssen.de
Thu Sep 17 11:07:53 EDT 2020


Hi Cristian,

did you try to apply a filter on both interfaces, i.e. add some accept-all
filter for lo0.0?

I read that the lo0.0 filter is also used in the other instances if there
is no own filter set, but not if this applies vice-versa (at least it
seams to be the case).

kind regards
Rolf

> Hi
> I am trying to create a firewall filter to protect the routing engine
> only in a routing-instance, and with that I apply the firewall filter
> in the lo0.1 interface.
> I noticed that when applying the filter that in theory should only
> apply to the routing-instance, it also ends up dropping packets that
> come to lo0.0, is Junos supposed to work that way?
>




More information about the juniper-nsp mailing list