Actually, you shoul be able to create and apply one. As JColl said, it does not support statefull firewall filtering. You can create Port, VLAN and RVI filters (L2/L3). There is lots of flexibility in creating these firewall filters. You have understand how the terms are evaluated. It is not quite as simple as it sounds. But for now try this:
{master:0}[edit firewall family ethernet-switching]
lab@exA-2# show
filter block-some-ports {
term other-ports {
from {
source-address {
0.0.0.0/0;
}
destination-address {
0.0.0.0/0;
}
destination-port 1024-65535;
}
then {
discard;
log;
}
}
term allow-other-ports {
then accept;
}
}
{master:0}[edit firewall family ethernet-switching]