I have created a firewall filter that discards or stops echo-replies under icmp-type.
Tested from external, after applying the firewall filter to the required interface and it seemed to work. To ensure this works as expected, I need to get the circuit owner to test from the CPE end. As soon as this is completed I will be able to let you know if it was fully successful or not.... Here is the config applied:
set firewall family inet filter filter-tracert term 1 from source-address 0.0.0.0/0
set firewall family inet filter filter-tracert term 1 from destination-address (Internal subnet)
set firewall family inet filter filter-tracert term 1 from protocol icmp
set firewall family inet filter filter-tracert term 1 from icmp-type echo-reply
set firewall family inet filter filter-tracert term 1 then discard
set firewall family inet filter filter-tracert term 2 then accept
set interface ae1 unit 0 family inet filter input filter-tracert
If you see any issues with this then please let me know: