> might be - I've never used virtual routers. a firewall input filter on > fxp0 is just in the kernel (obviously not in the PFE ASICs), but it > works well. :)
I was more in the line on if I want separate routing for my RE port from the rest of the network, so that I can build a route management network and routes wont mix that up from the "real" network. Management will still be available from the normal network, so lo0 firewall filter is a good idea out of security. Cheers Patrik _______________________________________________ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp