SRX

last person joined: 4 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  SRX3600 SCTP Sec policy junos-gprs-sctp vs junos-sctp-any

    Posted 02-23-2017 03:36

    Hi,

     

    we're about to configure some security policies on a SRX3600 box  for SCTP traffic

     

    So far the security policy is buit-up with the src&dest ip subnets and application set to junos-sctp-any

     

    i just came across to the junos-gprs-sctp statement.

     

    my question is. is it really necessary to configure the junos-gprs-sctp and profile vs using a tradicitional security policy configuration permitting just the junos-sctp-any service?

     

    Thanks in advance.

    BR

    Gab



  • 2.  RE: SRX3600 SCTP Sec policy junos-gprs-sctp vs junos-sctp-any
    Best Answer

     
    Posted 02-23-2017 09:47
    AFAIK you need a sctp profile only if yoy need the SCTP deeper inspection otherwise you just need the security policy

    ref - https://www.juniper.net/techpubs/en_US/junos12.1x44/topics/concept/gprs-sctp-configuration-overview.html





  • 3.  RE: SRX3600 SCTP Sec policy junos-gprs-sctp vs junos-sctp-any

    Posted 02-24-2017 01:54

    Clear enough. Thanks!!