Concept and mechanism
A routing policy evaluates routes; a firewall filter evaluates packets. Import and export in routing context handle acceptance or advertisement of information rather than simply meaning incoming and outgoing traffic on a port. Policy organizes terms, conditions, and actions. An isolated route-filter 10.50.0.0/16 exact condition requires that prefix and length; a contained /24 does not match. Qualifiers such as orlonger change scope and need review. Routing-protocol defaults should not be transferred to filters either: in a firewall filter, a packet matching no term encounters implicit discard at the end.
Guided application
In a fictional hardening scenario, only SSH was permitted and NTP stopped working. The team should inventory required services, create scoped terms, and test permissions and denials while retaining recovery. An unrestricted final accept can restore connectivity while removing the control objective. Stateless filters also do not automatically create a session authorizing all return traffic; examine applicable controls in both directions. In production, confirm family, interface, direction, and counters to know where policy acts. RPF and platform-specific behavior need further study beyond this introduction. Acceptance should state what was rehearsed and which cases remain uncovered so RUN does not discover a legitimate dependency only during daily close.
A filter accepting only SSH can discard NTP because no matching term exists.
Common pitfalls
Export as egress port; exact as any subprefix; routing default as filter default; stateless as session state.
Related topics: Addressing and capacity · Junos planes and state interpretation · CLI, candidate, and rollback
Test final action on the correct object.
Reference: Routing policies versus firewall filters · JN0-106, effective 2026-04-06; Junos OS 21.2 exam baseline