Log in to ask questions, share your expertise, or stay connected to content you value. Don’t have a login? Learn how to become a member.
Hi all,
I'm working a lot with SRX, and i have a doubt: the firewall sessions and NAT session are in PFE or in the RE?
I think that NAT keep in the RE and the firewall sessions are in the PFE (i'm associating the basic concept of PFE and firewall filters). Someone could clarify this, please?
Tks all.
João Victor
Hi
Flow module, which is part of PFE, takes care of firewall sessions and NAT.
RE does not process transit traffic in Junos-based devices.
Great!
Good to know!!! Tks a lot for your answer!
I should think as: "The traffic inspected by firewall rules are transit traffic, so as consequence, this is verified by PFE"!! I'm a looser
Tks a lot for your patience 🙂