Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: One-way SCTP thru SRX345 on JunOS 15.1X49-D50.3

$
0
0

Hi,

 

It looks like the SRX is not detecting the application for this traffic and probably reading this as TCP packets.

 

Dynamic application: junos:UNKNOWN

_____________________________________________

 

The policy allows any traffic between two peers

_____________________________________________

Is the security policy matching "application any"?

 

I would suggest defining an explicit security policy for sctp using application junos-gprs-sctp because sctp handshake is different to tcp.

https://www.juniper.net/documentation/en_US/junos12.1x47/topics/example/gprs-sctp-policy-based-inspection-configuring.html

 

Also note:

  • You configure one policy to permit SCTP traffic from all client IPs to all server IPs, and another policy to permit SCTP traffic from server IPs to client IPs. If one policy has an SCTP profile, then the same SCTP profile is needed for the reverse policy.

Cheers,

Ashvin


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>