SRX Next-Gen Firewalls

 View Only
last person joined: 2 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.

Welcome!

If you have a question or a use case, likely there are others who are experiencing or worked through the same thing. Don't hesitate to jump in and ask or share your knowledge!

Need additional guidance?  Check out these Juniper Resources.

Juniper Threat LabsSRX Upgrade Guide Security Advisories Technical Bulletins

Latest Discussion Posts

  • There were error(s) delivering the configuration. Error(s): 'address 164.182.158.1/32' 1) Proxy ARP IP address range [164.182.158.1 164.182.158.254] overlaps with interface IP address range [164.182.158.254 164.182.158.254] defined on interface 'ge-0/0/0.0' ...

  • Only the remote site will specify an ip address, not the static/HQ side. This will have only the matching host name. See this short example of the differences. https://supportportal.juniper.net/s/article/SRX-Length-of-hostname-in-aggressive-mode-site-to-site-IPSec-VPN ...

  • HI Jay, As the Security Policy is processed after NAT, your source and destination addresses will both be the internal IPs. I have written an example out what your configuration for NAT and security policy would look like. (sorry if there's a typo, ...

  • For FBF Please refer the doc below: https://www.juniper.net/documentation/us/en/software/junos/routing-policy/topics/example/filter-based-forwarding-example.html If you have any questions wrt the config which you are making, please reach-out. ...

  • I did create an address book entry for both internal and external IP but when I try to ping the external ip from the the server it does not work I must be missing somthing I reverse the addresses just in case and that also did not work Srv-Mail-158.245 ...

  • Apologies for the double post. I got no confirmation from my first post. The 'any any' rule you mentioned that you have will be as effective as the more specific rule I provided as an example. The commit issue is because these source-address and destination-address ...

  • I can not commit I get this Warning(s): 'policy our-hairpin-policy,policy our-hairpin-policy' 1) Source address or address_set (10.10.20.0/24) not found. Please check if it is a SecProfiling Feed. 2) Destination address or address_set (10.10.20.0/24) ...

Unanswered Posts

Top Contributors in the Community