Support Support Downloads Knowledge Base Case Manager My Juniper Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[Junos] ARP-trigger is missing in the next-ip feature for FBF (Filter-Based Forwarding) from day one



Article ID: KB31274 KB Last Updated: 29 Nov 2016Version: 1.0

When next-ip is defined as the action and there is no ARP (Address Resolution Protocol) for the IP address specified under next-ip, the traffic is not forwarded. A manual ping needs to be initiated for things to work.


Example topology

FBF has been applied as input direction on interface ge-1/0/0 of router R2.

user@R2# show firewall 
filter fbf {
    term 1 {
        from {
            source-address {
        then {
    term 2 {
        then accept;

user@R2# show interfaces ge-1/0/0 
unit 0 {
    family inet {
        filter {
            input fbf;

Then start ping from R1.
All packets are dropped due to "Destination Net Unreachable":

user@R1# show routing-options static          
route next-hop;     

user@R1# run ping count 2 
PING ( 56 data bytes
36 bytes from Destination Net Unreachable
Vr HL TOS  Len   ID Flg  off TTL Pro  cks      Src      Dst
 4  5  00 0054 f084   0 0000  3f  01 7212 

36 bytes from Destination Net Unreachable
Vr HL TOS  Len   ID Flg  off TTL Pro  cks      Src      Dst
 4  5  00 0054 fa31   0 0000  3f  01 6865 

--- ping statistics ---
2 packets transmitted, 0 packets received, 100% packet loss  

When these packets arrive in R2, they are dropped because there is no ARP entry of and these packets cannot trigger the ARP process.

The next-ip feature works as designed from day one.

Take one of following actions to avoid this issue:
  1. Add a static route of "next-ip" with next-hop to itself, for example:

    user@R2# set routing-options static route next-hop

  2. Add a static ARP entry of "next-ip" in FBF filter.

    user@R2# set interfaces ge-1/0/1.0 family inet address arp mac xx:xx:xx:xx:xx:xx

Related Links

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search