Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: log traffic for the default deny policy not working

$
0
0

Hiegawd,

 

I was doing some testing on this and below are my findings.

 

1. RT_FLOW_SESSION_DENY is generated with "session-init" and not with "session-close". This makes sense the traffic was dropped while it was initiating. You need to modify the policy logging to include session-init

 

2. In your setup, we need policy to junos-host for this logs. Otherwise the traffic will hit self-traffic policy and wont hit the global policy.

 

Feel free to correct me if I have misunderstood any points here.

 

 

 

 

 

 


Viewing all articles
Browse latest Browse all 17645

Trending Articles