SRX Services Gateway
Highlighted
SRX Services Gateway

Policy hit-count

‎08-11-2015 02:38 PM

Hi,

 

Is it possible to get a policy hitcount on the Juniper SRX that shows a detailed hit count for the IPs defined in the policy? For instance, if host A is allowed access to hosts B, C and D; and if I show a hit count for the policy I want to be able to see the following:

1. host A to host B had 0 hits
2. host A to host C had 20 hits
3. host A to D had 0 hits

This allows me to see that I can cleanup the firewall and remove hosts A and C from the rule to make sure I do not have uneccesary rules in place. This is similar to what you get when you show an access-list in Cisco. Cisco firewalls report eac ACE within an ACL to make the firewall cleanup process easier. Does Juniper have anything like this to assist me in better cleaning up our firewalls?

Rakik
3 REPLIES 3
Highlighted
SRX Services Gateway

Re: Policy hit-count

‎08-11-2015 03:39 PM

The policy hit-count and policy count action are referencing the overall policy. To get more granular data you would need to break out the address book entries into separate policies.

 

Tim

Highlighted
SRX Services Gateway

Re: Policy hit-count

‎08-12-2015 06:06 AM

Hi ,

 

Will the SRX-session anayzer be helpful ?

 

Thanks

Rakik
Highlighted
SRX Services Gateway

Re: Policy hit-count

‎08-12-2015 06:23 AM

If you can create the traffic on demand, you should be able to see what you want with:

 

show security flow session soure-prefix [your source IP(s)] destination prefix [your destination IP(s)]

 

It will show the traffic entries as well as the policy it's hitting like this:

 

root@FW1A> show security flow session source-prefix 192.168.25.201/26 destination-prefix 192.168.28.8      
node0:
--------------------------------------------------------------------------

Flow Sessions on FPC6 PIC0:

Session ID: 12108681, Policy name: webserver-to-backup/17, State: Active, Timeout: 246, Valid
  In: 192.168.25.201/53736 --> 192.168.28.8/80;tcp, If: reth1.384, Pkts: 8, Bytes: 5739
  Out: 192.168.28.8/80 --> 192.168.25.201/53736;tcp, If: reth1.58, Pkts: 9, Bytes: 2659