Skip to Content
Juniper SRX Series
book

Juniper SRX Series

by Rob Cameron, Brad Woodberg
June 2013
Intermediate to advanced
1018 pages
28h 48m
English
O'Reilly Media, Inc.
Content preview from Juniper SRX Series

Chapter 8. Security Policies

Security policies are at the core of applying the security mechanisms of the SRX. This makes logical sense because of the granular, flexible nature of the firewall rulebase. Up until this point, we have had various discussions about the platform-level support of the SRX, but now, as we enter the second half of the book, we focus in on the actual application of security features.

In this chapter, we begin by quickly reviewing the packet flow of the SRX, followed by a discussion of the related security policy components, and an in-depth discussion of the SRX policy configuration itself. We explore some additional security policy features like the Level 7 security features and ALGs. We conclude this chapter with some hands-on discussions of best practices, troubleshooting and device operations, and sample deployments. By the end of this chapter, you should be a pro at not only configuring security policies, but also properly designing an effective security policy in your network.

Packet Flow

Earlier in the book we reviewed the packet flow of an SRX, but it is helpful to briefly discuss it here as a refresher (or if you’re just reading this chapter out of the book by itself).

Figure 8-1 gives us a visual representation of the security policy. When it comes to security policy enforcement on the SRX, this is entirely handled on the data plane of the SRX, unlike ScreenOS, which would do at least the policy lookup on the control plane. Completely leveraging the ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Juniper MX Series

Juniper MX Series

Douglas Richard Hanks Jr., Harry Reynolds
Juniper MX Series, 2nd Edition

Juniper MX Series, 2nd Edition

Douglas Richard Hanks, Harry Reynolds, David Roy

Publisher Resources

ISBN: 9781449339029Errata Page