This article outlines key considerations to review when configuring a firewall filter. If the filter is applied to an interface without proper validation, it may drop packets and negatively affect services.
When configuring a new firewall filter to capture or filter packets, or to implement filter-based forwarding, there is a risk that it may affect all traffic, whether it matches the filter criteria or not.Packets that do not meet the specified conditions will be dropped silently unless a counter is set up to track the number of dropped packets.
If you intend to perform packet capture using a firewall filter, please ensure the following criteria are met:
Finally, If an outage is caused by these firewall filter configurations, please roll back immediately and review the points above before proceeding with any planned maintenance. If making changes to the firewall filter on the fly, remember to use the commit confirm command.
2024-05-28 : Article Created
2024-09-28: Article modified
2026-03-18: Category updated