This message was posted by a user wishing to remain anonymous
Hi,
My SRX320 is in flow mode, and one of the devices on the network uses NetBios name services over UDP port 137 to connect to a server in irb.4. Flowmode blocks these packets so to resolve this I applied the bypass_flowd firewall filter
(link to juniper article) which listens for the NetBios traffic and changes it to packet mode so it gets passed to the server where it needs to connect to (server and client are in different irb's). When I upgraded from Junos v19 to v20 (or newer) the bypass filter no longer works and the count c1 doesnt increment.
Has anyone ever come across this issue before and how did you resolve it please, or pointers to where I should look and see why the traffic isn't matching?
Filter applied on the SRX:
set interfaces irb unit 4 family inet filter input bypass_flowd
set firewall family inet filter bypass_flowd term t1 from source-address 10.233.216.129/32
set firewall family inet filter bypass_flowd term t1 from protocol udp
set firewall family inet filter bypass_flowd term t1 from source-port 137
set firewall family inet filter bypass_flowd term t1 then count c1
set firewall family inet filter bypass_flowd term t1 then packet-mode
set firewall family inet filter bypass_flowd term t1 then syslog
set firewall family inet filter bypass_flowd term t4 then count t4
set firewall family inet filter bypass_flowd term t4 then accept
set firewall family inet filter bypass_flowd term t3 then accept
Thanks in advance,