Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: SRX w/ multiple routes/paths

$
0
0

As you notice, stateful firewalls really don't like asymmetrical flow traffic.  In this type of situation you have two options.

 

Place both uplink interfaces into the same security zone.  This will allow the session table to still match even when traversing both links.

 

Use source nat to the interface address on the inbound flows from uplink B.  This will force the return traffic to come back to the uplink B interface and complete a symmetrical path.


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>