SRX

 View Only
last person joined: 2 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  security policy Index number

    This message was posted by a user wishing to remain anonymous
    Posted 03-21-2024 02:57
    This message was posted by a user wishing to remain anonymous

    When I run the command:
    show security policies detail


    one of the datum displayed about the policies is the Index, in this example, 78:

    Policy: named-policy-1, action-type: permit, services-offload:not-configured , State: enabled, Index: 78, Scope Policy: 0


    How is the Index number assigned?
    Are Index numbers ever reused?
    If so, when are they reused?



  • 2.  RE: security policy Index number

    Posted 03-22-2024 12:13

    Each policy gets assigned a unique index number. I believe they start from 1 and go up with each policy, but the sequence in which an index is assigned to policies doesn't seem to follow any particular pattern. I haven't paid too much attention to see if the index number survives a reboot, but my guess is that it's not guaranteed to remain the same across reboots. If you come from the ScreenOS world, you'll surely recall the policy ID there became part of the config, forever set. Not so in JunOS. 

    The index is useful for filtering session by policy index, and ... well, that's all that comes to mind really. You'd see it in policy traces, too, though policy names are listed there as well.



    ------------------------------
    Nikolay Semov
    ------------------------------



  • 3.  RE: security policy Index number

    Posted 03-22-2024 17:09

    In a network that globally omits your NA setup such as my isp, the traffic won't flow because of dns. Clusters are the culprit. Policies like that in switches are hard to manage. Reset comes to mind.



    ------------------------------
    Adrian Aguinaga
    B.S.C.M. I.T.T. Tech
    (Construction Management)
    A.A.S. I.T.T. Tech
    (Drafting & Design)
    ------------------------------