SRX

last person joined: 3 hours ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  Firewall / NAT table - RE or PFE?

    Posted 09-05-2016 11:24

    Hi all,

    I'm working a lot with SRX, and i have a doubt: the firewall sessions and NAT session are in PFE or in the RE?

     

    I think that NAT keep in the RE and the firewall sessions are in the PFE (i'm associating the basic concept of PFE and firewall filters). Someone could clarify this, please?

     

    Tks all.

     

    João Victor



  • 2.  RE: Firewall / NAT table - RE or PFE?
    Best Answer

    Posted 09-05-2016 12:27

    Hi

     

    Flow module, which is part of PFE, takes care of firewall sessions and NAT.

    RE does not process transit traffic in Junos-based devices.



  • 3.  RE: Firewall / NAT table - RE or PFE?

    Posted 09-09-2016 08:19

    Great!

     

    Good to know!!! Tks a lot for your answer! Smiley Wink

     

    I should think as: "The traffic inspected by firewall rules are transit traffic, so as consequence, this is verified by PFE"!! I'm a looser

     

    Tks a lot for your patience 🙂

    João Victor