Security Policy
A security policy is a set of statements, or rules, that controls traffic from a specified
source (source-address and optionally source-identity) to a specified destination
(desitnation-address) using a specified service (application). If the SRX Series device
receives a packet that matches the specifications of one of the rules in the security policy,
the SRX Series performs on the packet the action defined by that policy rule.
provides details of factory default settings for security policies on
branch SRX Series devices.
Table 7: Factory-Default Settings for Security Policies for Branch SRX Series Devices
Action
To Zone
From Zone
Allow
Untrust zone
Trust zone
Allow
Trust zone
Trust zone
Deny
Trust zone
Untrust zone
For more details on security policies, see
Building Blocks Feature Guide for Security Devices
.
Related
Documentation
Understanding Factory Default Configuration Settings of an SRX210 on page 7
•
•
Connecting Your Branch SRX Series for the First Time
•
Example: Configuring Security Zones and Policies for SRX Series on page 32
Example: Configuring Security Zones and Policies for SRX Series
This example shows how to set up a new zone and add three application servers to that
zone. Then you provide communication between a host (PC) in the trust zone to the
servers in the newly created zone and also facilitate communication between two servers
within the zone.
To meet this requirement, you need an interzone security policy to allow traffic between
two zones and an intrazone policy to allow traffic between servers within a zone.
Requirements
This example uses the following hardware and software components:
•
An SRX210
•
Junos OS Release 12.1X44-D10
Overview
This example uses the network topology shown in
.
Copyright © 2016, Juniper Networks, Inc.
32
Getting Started Guide for Branch SRX Series
Содержание Junos OS
Страница 6: ...Copyright 2016 Juniper Networks Inc vi Getting Started Guide for Branch SRX Series...
Страница 8: ...Copyright 2016 Juniper Networks Inc viii Getting Started Guide for Branch SRX Series...
Страница 10: ...Copyright 2016 Juniper Networks Inc x Getting Started Guide for Branch SRX Series...
Страница 17: ...PART 1 Overview Introduction to SRX Series Devices on page 3 1 Copyright 2016 Juniper Networks Inc...
Страница 18: ...Copyright 2016 Juniper Networks Inc 2 Getting Started Guide for Branch SRX Series...
Страница 20: ...Copyright 2016 Juniper Networks Inc 4 Getting Started Guide for Branch SRX Series...
Страница 22: ...Copyright 2016 Juniper Networks Inc 6 Getting Started Guide for Branch SRX Series...
Страница 32: ...Copyright 2016 Juniper Networks Inc 16 Getting Started Guide for Branch SRX Series...
Страница 42: ...Copyright 2016 Juniper Networks Inc 26 Getting Started Guide for Branch SRX Series...
Страница 44: ...Copyright 2016 Juniper Networks Inc 28 Getting Started Guide for Branch SRX Series...
Страница 46: ...Copyright 2016 Juniper Networks Inc 30 Getting Started Guide for Branch SRX Series...
Страница 54: ...Copyright 2016 Juniper Networks Inc 38 Getting Started Guide for Branch SRX Series...
Страница 62: ...Copyright 2016 Juniper Networks Inc 46 Getting Started Guide for Branch SRX Series...
Страница 78: ...Copyright 2016 Juniper Networks Inc 62 Getting Started Guide for Branch SRX Series...
Страница 86: ...Copyright 2016 Juniper Networks Inc 70 Getting Started Guide for Branch SRX Series...
Страница 90: ...Copyright 2016 Juniper Networks Inc 74 Getting Started Guide for Branch SRX Series...
Страница 155: ...PART 5 Index Index on page 141 139 Copyright 2016 Juniper Networks Inc...
Страница 156: ...Copyright 2016 Juniper Networks Inc 140 Getting Started Guide for Branch SRX Series...