You can create standard and extended Layer 3 (IPv4 and IPv6) ACLs, and define permit and deny rules within them.
          ACLs now support filtering fragmented and non-fragmented packets. Use the
          fragment or non-fragment keywords to enable filtering out these
          packets. Filtering on fragment and non-fragment packets is not supported in SLX 9150
          and SLX 9250.   
      
See also Advanced Layer 3 ACL rules and features.