SRX

last person joined: yesterday 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
Expand all | Collapse all

SRX has security policy with a certain action and a firewall filter with a certain action matching the same traffic?

  • 1.  SRX has security policy with a certain action and a firewall filter with a certain action matching the same traffic?

    Posted 12-15-2014 11:10

    Which way will the SRX choose to filter traffic?

    Also, if firewall filters are stateless, if I want to enable traffic between 2 zones, does it mean I have to apply to firewall filters; one in each direction(interface) in order to pass traffic?

     

    Thanks in advance



  • 2.  RE: SRX has security policy with a certain action and a firewall filter with a certain action matching the same traffic?
    Best Answer

     
    Posted 12-15-2014 11:24

    I think your answer depends on what it is you are trying to do with the firewall filter.  If you are accepting the traffic with the filter, then you have essentially allowed that traffic through the flow module in the SRX for further processing.  If you explicitly deny the traffic with the firewall filter, then nothing else happens - the traffic is dropped right there at the ingress interface with no further processing.

     

    Using firewall filters for traffic filtering on the SRX is not exactly common, even in a "belts and suspenders" type of environment.  In the "filtering" context, firewall filters are used as a first line of defense to prevent unnecessary processing by the flow module, or for selective stateless packet filtering where you want stateless filtering done on incoming traffic which will allow the transit traffic, but bypass the flow module altogether. In the case of selective stateless filtering, then you do need matching bi-directional input filters for the traffic on the ingress and egress interfaces.