Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: SRX firewall routing configuration

$
0
0

Q, do those definitions in global configuration, defined as routing-options static route

Interact with Zones or Security Policies?

                Or is it only for the basic functionality related to the Firewall as a device (I mean, for the syslog/NTP/… accessibility)

 

The routing helps to determine which zone is involved with a flow which then determines which security policy will apply.

 

When a packet arrives, the ingress interface belongs to a zone, this is the from-zone for the policy check.

A route lookup occurs for the destination address, this determines then the egress interface for the traffic and the zone assigned to this interface is the to-zone in the policy check.


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>