On Juniper Router's if you want to sample all traffic, you don't really need a firewall filter, you can use the following simple form: ge-0/0/0 { unit 0 { family inet { sampling { input; } } } } Packet sampling can also be done by defining a firewall