On (2014-01-31 11:02 +0200), Alexander Kasatkin wrote: > But I don't have any reject action in firewall rules. Please point me > to right direction.
This would be any packet which has DADDR pointing to FIB entry with type 'reject'. In more practical terms, destination to which you don't have route for. show route forwarding-table family inet table default destination 0.0.0.0/0 In typical DFZ router would be 'rjct'. -- ++ytti _______________________________________________ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp