SRX

last person joined: yesterday 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  zone_id vs name

    Posted 04-13-2016 03:24

    Hi,

     

    Making a traceoption under security alg, we've received output, which is not clear. Is there any possibility how to recognize the relation between the (src_\dst_)zone_id with its canonical name. The same for the lsys name. Of course it can be done manually, reviewing all the logs, routing etc, but I'm looking for more convenient way to do this.

     

    Apr 13 08:10:10 08:10:10.243487:CID-01:FPC-01:PIC-00:THREAD_ID-17:RT:jsf_msrpc_alg_check_policy_by_map: lookup poicy for: lsys: 2, v_src_port:32768, v_dst_port:2, src_zone_id = 51,dst_zone_id = 48, src addr:x.x.x.x, dst addr:....

     

    thanks in advance,

    Radek



  • 2.  RE: zone_id vs name
    Best Answer

    Posted 04-13-2016 03:27

    Dear Radek,

     

    Not sure if this is what you are looking for but you can try this one:

    start shell
    cd /var/etc
    cat security_zone.id and search your zone


  • 3.  RE: zone_id vs name

    Posted 04-13-2016 03:43

    Dear Michal,

     

    Thank you for pointing into solution. You're right 🙂

     

    thank you:)