Description

Configuring the policy with no-services-offload

Solution

When a policy profile is created, Junos Space creates an object in the Junos Space database to represent the policy profile. You can use this object to create security policies.

To configure a policy profile with service offload:

  • Login to SD UI
  • Select Configure > Firewall Policy > Profiles.
  • Click the + icon.

Under there there is an advance setting from where the service offload can bee set.

 

Advance Settings

Services Offload

Select from the following options:

  • None—Select to delete the configured service from the device.

  • Enable—Select to enable services offload. When services offload is enabled, only the first packets of a session go to the SPU. The rest of the packets in services offload mode do not go to the SPU; therefore, some security features such as stateful screen are not supported. You can offload services only for TCP and UDP packets.

  • Disable—Select to disable services offload.

Note: 

Both logical systems and tenant systems support the disable services offload feature.

    • Click OK.

    A new policy profile with the predefined policy configurations is created. You can use this object in security policies.

     

    Modification History

    2025-07-18 : Article Created