filmov
tv
MicroNugget: What are SRX Security Flows?
![preview_player](https://i.ytimg.com/vi/xcknteFCul4/maxresdefault.jpg)
Показать описание
In this video, Scott Morris covers JUNOS SRX security flows. When packets arrive, a router or security gateway has certain policies and tables that help decide what to do with those packets. This video helps explain the flow of lookups and decisions a device makes to maintain security.
Scott uses a flow chart to help demonstrate the JUNOS security model and what happens to packets entering a security gateway. First, they pass through the stateless filters and policers and they're checked to see if a session already exists for them. If not, a series of lookups is performed to determine what's to be done with them. This includes firewall policies, destination-NAT, routing, zones based on ingress/egress, routing policies, source-NAT, and application layer group configuration.
With the results of those lookups, a session is created. No policies have been applied at this point — that treatment requires a session. The session table is where the information is stored about what to apply to each packet: firewall options, basic TCP features, NAT features and ALG services. From there, stateless output filters and shapers can be applied, and the security process has run its course.
Start learning with CBT Nuggets:
Комментарии