Hello,
I am testing a simple ICMP firewall filter on a qfx5100-48s-6q and cannot commit after I apply the filter on a layer2 interface. The commit works however after I apply it on a layer 3 interface.
interfaces {
ge-0/0/0 {
unit 0 {
family ethernet-switching {
interface-mode access;
vlan {
members TEST;
firewall {
family inet {
filter RA-FILTER {
term SSH {
from {
source-address {
69.54.49.182/32;
}
protocol tcp;
destination-port ssh;
}
then {
count allow.ssh;
accept;
}
}
}
filter ICMP-FILTER {
term ICMP {
from {
source-address {
192.168.99.50/32;
}
}
then accept;
}
term ICMP-BLOCK {
from {
protocol icmp;
}
then {
discard;
}
}
term ALLOW {
then accept;
atetu@emp-cle.qfx5100-1#set interfaces ge-0/0/0 unit 0 family ethernet-switching filter input ICMP-FILTER
atetu@emp-cle.qfx5100-1# commit
[edit interfaces ge-0/0/0 unit 0 family ethernet-switching]
'filter'
Referenced filter 'ICMP-FILTER' is not defined
error: configuration check-out failed
ge-0/0/10 {
unit 0 {
family inet {
address 10.10.200.254/24
atetu@emp-cle.qfx5100-1# ...erfaces ge-0/0/10 unit 0 family inet filter input ?
Possible completions:
ICMP-FILTER [firewall family inet filter] ---- this don't show above on the Ge0/0/0 layer2 interface
RA-FILTER [firewall family inet filter] -------- this don't show above on the Ge0/0/0 layer2 interface
Thanks,
-Adrian