Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

Enhancements to configuring security policies

More Information:

Enhancements to configuring security policies

Junos OS supports advanced-connection-tracking command under the [edit security zones security-zone zone name] and [edit security policies from-zone zone-name to-zone zone-name policy policy-name then permit] hierarchy levels. The advanced-connection-tracking option under [edit security zones security-zone zone name]enable the action to generate connection track table using source IP, destination IP(optional), and destination port(optional) during session creation stage when traffic ingress given zone. This connection track mapping table also appears on backup node in HA(High Availability) pair. The advanced-connection-tracking option under [edit security policies from-zone zone-name to-zone zone-name policy policy-name then permit] mandate that traffic matching given policy will do a lookup in to-zone's connection track mapping table using the new session's key information, if there is no match, new connection will not be created.
Product / Application Software Introduced Release
vSRX Junos OS 25.4R1
vSRX Junos OS 20.2R1
cSRX Junos OS 25.4R1
cSRX cSRX 20.2R1
SRX300 Junos OS 25.4R1
SRX300 Junos OS 20.2R1
SRX320 Junos OS 25.4R1
SRX320 Junos OS 20.2R1
SRX340 Junos OS 25.4R1
SRX340 Junos OS 20.2R1
SRX345 Junos OS 25.4R1
SRX345 Junos OS 20.2R1
SRX380 Junos OS 25.4R1
SRX380 Junos OS 20.2R1
SRX550 HM Junos OS 20.2R1
SRX1500 Junos OS 25.4R1
SRX1500 Junos OS 20.2R1
SRX1600 Junos OS 23.4R1
SRX2300 Junos OS 23.4R1
SRX4100 Junos OS 25.4R1
SRX4100 Junos OS 20.2R1
SRX4120 Junos OS 25.2R1
SRX4200 Junos OS 25.4R1
SRX4200 Junos OS 20.2R1
SRX4300 Junos OS 24.2R1
SRX4600 Junos OS 25.4R1
SRX4600 Junos OS 20.2R1
SRX4700 Junos OS 24.4R1-S2
SRX5400 Junos OS 25.4R1
SRX5400 Junos OS 20.2R1
SRX5600 Junos OS 25.4R1
SRX5600 Junos OS 20.2R1
SRX5800 Junos OS 25.4R1
SRX5800 Junos OS 20.2R1