SRX

last person joined: 3 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
Expand all | Collapse all

Does a permit statment within an SRX Zone Context automatically create a statful inspection entry for return TCP traffic?

  • 1.  Does a permit statment within an SRX Zone Context automatically create a statful inspection entry for return TCP traffic?

    Posted 04-11-2014 06:33

    Hi All,

     

    I am brand new to Juniper and I have been reading up on Zones and policies for the SRX series and as far as I can see from the docs I have been reading, you need to specify Zone transit policies in both directions rather than just one way and then allowing stateful inspection to keep track of the return TCP traffic as you do with Cisco.

     

    I can't believe this would be the case however as the policy options are to Permit, Deny or Reject.

     

    I am assuming the Permit statement automatically includes stateful rememberance of the TCP session to allow inbound traffic back in to the originating Zone without a policy having to be explicitly applied for return traffic

     

     

    If someone could kindly confirm this for me it would be much appreciated

     

    MItch


    #policy
    #SRX
    #context
    #Stateful
    #zones


  • 2.  RE: Does a permit statment within an SRX Zone Context automatically create a statful inspection entry for return TCP traffic?
    Best Answer

    Posted 04-11-2014 06:43

    Hi,

     

    The SRX is stateful, the security policy defines the initial packet parameters as the match criteria, and will automatically allow the return traffic for the session by installing a reverse session “wing”.  So as you say, you do not need to configure a reverse policy or a policy for the return traffic.

     

    When you execute a "show security flow session", you will see both wings of any active session installed in the session table.

     

    Have a read below:

     

    http://kb.juniper.net/InfoCenter/index?page=content&id=KB16553

     

    http://kb.juniper.net/InfoCenter/index?page=content&id=KB21719

     



  • 3.  RE: Does a permit statment within an SRX Zone Context automatically create a statful inspection entry for return TCP traffic?

    Posted 04-11-2014 07:02
    It does stateful inspection. No need to specify return policy...


  • 4.  RE: Does a permit statment within an SRX Zone Context automatically create a statful inspection entry for return TCP traffic?

    Posted 02-18-2015 05:01
    Agreed with AVD