SRX Services Gateway
Highlighted
SRX Services Gateway

Allow TCP half-completed connection on SRX

‎07-06-2014 06:57 PM

Hi guys

As we all know the firewall needs to see both directions of a flow (client-server and server-client), otherwise these checks will block legitimate packets.

In my network  there is a real requirement that  one of the both directions of a flow (server-client)through the firewall.

I want to permit the traffic half-completed connection,how i go ahead ?

Thanks !

4 REPLIES 4
Highlighted
SRX Services Gateway

Re: Allow TCP half-completed connection on SRX

‎07-06-2014 07:32 PM

Hi ,

 

You can try disabling "syn-check" and "seq-check"

 

set security flow tcp-session no-syn-check
set security flow tcp-session no-sequence-check

 

Thanks,

Suraj

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: Allow TCP half-completed connection on SRX

‎07-06-2014 07:51 PM

Highlighted
SRX Services Gateway
Solution
Accepted by topic author Nicolash·q
‎08-26-2015 01:27 AM

Re: Allow TCP half-completed connection on SRX

‎07-06-2014 09:49 PM

Hi Nicolash-q,

 

I dont think ,half opened connections can be kept on the SRX.it will drop it within few seconds.

 

But as a work around , you can use selective packet mode for that traffic using firewall filter:

 

Using this technique, you can use both packet mode for this stream  and flow mode for rest.


set firewall filter PACKET-MODE term 1 from source-address X.X.X.X/32

set firewall filter PACKET-MODE term 1 from destination-address y.y.y.y/32

set firewall filter PACKET-MODE term 1 then packet-mode

set firewall filter PACKET-MODE term 2 then accept

 

Now apply the filter PACKET-MODE in required interface in inbound or outbound direction.

 

So traffic coming from particular source address of X.X.X.X/32 will only be processed as packet mode by SRX, rest will be processed as flow mode.

 

Regards
rparthi
 

Please Mark My Solution Accepted if it Helped, Kudos are Appreciated Too

Highlighted
SRX Services Gateway

Re: Allow TCP half-completed connection on SRX

‎07-07-2014 12:58 AM

Yeah, It is the only solution.

 

Thank you!

Feedback