Configuring Stateful Firewalls for Next Gen Services | Junos OS (2024)

To configure stateful firewalls, you configure statefulfirewall rules, and apply those rules to a service set. You can alsoconfigure stateful firewall rule sets, which contain a set of statefulfirewall rules.

Configuring Stateful Firewall Rules for Next Gen Services

A stateful firewall rule specifies which traffic is processedand what action to apply to the traffic.

To configure a stateful firewall rule:

  1. Configure a name for the stateful firewall rule.
  2. Specify the traffic flow direction to which the statefulfirewall rule applies.

    If you configure input-output, the rule is appliedto sessions initiated from either direction.

    If this stateful firewall rule is applied to an interface-typeservice set, the direction is determined by whether a packet is enteringor leaving the interface on which the service set is applied. If thisstateful firewall rule is applied to a next-hop service set, the directionis input if the inside interface is used to route the packet, andthe direction is output if the outside interface is used to routethe package.

  3. Configure a name for a policy.

    You can configure multiple policies for a stateful firewallrule. Each policy identifies the matching conditions for a flow, andwhether or not to allow the flow. Once a policy in the rule matchesa packet, that policy is applied and no other policies in the ruleare processed.

  4. Specify the destination address of the flows to whichthe policy applies.

    Alternatively, you can specify an address-book underthe services configuration hierarchy to use in this step.

    The destination address can be IPv4 or IPv6.

  5. Specify the destination address of the flows to whichthe policy does not apply.

    The destination address can be IPv4 or IPv6.

  6. Specify the source address of the flows to which the policyapplies.

    Alternatively, you can specify an address-book underthe services configuration hierarchy to use in this step.

    The source address can be IPv4 or IPv6.

  7. Specify the source address of the flows to which the policydoes not apply.

    The source address can be IPv4 or IPv6.

  8. Specify one or more application protocols to which thepolicy applies.

    Use an application protocol definition you have configured atthe [edit applications] hierarchy level.

  9. Specify an action that the policy takes.

    where:

    count

    Enables a count,in bytes or kilobytes, of all network traffic the policy allows topass.

    deny

    Drop the packets.

    permit

    Accept thepackets and send them to their destination.

    reject

    Drop the packets.For TCP traffic, send a TCP reset (RST) segment to the source host.For UDP traffic, send an ICMP destination unreachable,port unreachable message (type 3, code 3) to the sourcehost.

Configuring Stateful Firewall Rule Sets for Next Gen Services

A stateful firewall rule set lets you specify a set of statefulfirewall rules, which are processed in the order in which they appearin the rule set configuration. Once a stateful firewall rule in therule set matches a packet, that rule is applied and no other rulesin the rule set are processed˙.

To configure a stateful firewall rule set:

  1. Configure a name for the stateful firewall rule set.
  2. Specify the stateful firewall rules that belong to therule set.

Configuring the Service Set for Stateful Firewalls for NextGen Services

Stateful firewall rules must be assigned to a service set beforethey can be applied to traffic.

To configure a service set to apply stateful firewallrules:

  1. Define the service set.
  2. Configure either an interface service set, which requiresa single service interface, or a next-hop service set, which requiresan inside and outside service interface.

    or

  3. Specify the stateful firewall rules to be used with theservice set. You can specify either individual rules or rule setsbut not both.

    To apply individual stateful firewall rules:

    To apply stateful firewall rule sets:

    The service set processes the stateful firewall rules or rulesets in the order in which they appear in the service set configuration.

Configuring Stateful Firewalls for Next Gen Services | Junos OS (2024)
Top Articles
Latest Posts
Article information

Author: Dong Thiel

Last Updated:

Views: 6095

Rating: 4.9 / 5 (79 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Dong Thiel

Birthday: 2001-07-14

Address: 2865 Kasha Unions, West Corrinne, AK 05708-1071

Phone: +3512198379449

Job: Design Planner

Hobby: Graffiti, Foreign language learning, Gambling, Metalworking, Rowing, Sculling, Sewing

Introduction: My name is Dong Thiel, I am a brainy, happy, tasty, lively, splendid, talented, cooperative person who loves writing and wants to share my knowledge and understanding with you.