I don't see the term you are mentioning in the initial post:
user@router> show configuration firewall
family inet {
filter demo {
term example {
from {
source-address {
100.100.100.0/24;
}
destination-address {
200.200.200.0/24;
}
}
then {
reject;
}
}
term testing {
from {
source-address {
10.10.10.0/28;
}
destination-address {
200.200.200.0/24;
}
}
then sample;
}
term results {
from {
address {
200.200.200.0/24;
}
}
then accept;
}
term final {
then policer LAPD;
}
}
}
The term mentioned by me as being correct says something like "if the source or destination fails in the range 200.200.200.0/24, then accept the packet'. It would have been the same thing if instead of 200.200.200.0/24, you would had 10.10.10.0/24.
=====
If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.