Virtual interfaces in Solaris are very similar, to filter on them, use the physical interface instead.
Not entirely true. For example, when doing IPSec on Solaris, one needs to filter on ip.tun0 or whichever interface one configured as the tunnel (ip.tun3, ip.tun7 etcetera).
