SRX Services Gateway
Showing results for 
Search instead for 
Do you mean 
Reply
New User
Posts: 1
Registered: ‎01-22-2012
0 Kudos

Change the security policy then take effect immediate ?

 

 

 

When we change the security policy on SRX, the device doesn't take effect immediate.Also can say,the already exist  sessions are not take effect.So how do we do,let the device take effect immediate when we change the security policy ?

 

 

Thanks

 

 

 

Distinguished Expert
Posts: 3,900
Registered: ‎03-30-2009

Re: Change the security policy then take effect immediate ?

The default behavior is that when a policy is modified the new version only applies to sessions created after this change is committed.

You can configure the policy-rematch parameter.  This will check sessions again when a policy is modified and committed.  If the action is changed then all sessions are dropped and will be reevaluated as they are created.

set security policies policy-rematch

 

Steve Puluka BSEET
Juniper Ambassador
Senior IP Engineer - DQE Communications Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC JNCSP-SEC
JNCIS-FWV JNCIS-SSL JNCDA
JNCIS-SP
ACE PanOS 6
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home