Root@SRX210# show interfaces { ge-0/0/0 { unit 0 { family inet { filter { input fbf; } address 192.168.0.254/24; } } } ge-0/0/1 { unit 0 { family inet { address 172.27.103.42/24; } } } fe-0/0/4 { unit 0 { family inet { address 173.27.103.42/24; } } }}...routing-options { interface-routes { rib-group inet rib1; } rib-groups { rib1 { import-rib [ inet.0 lab.inet.0 desktop.inet.0 ]; } }}policies { from-zone trust to-zone lab { policy p1 { match { source-address any; destination-address any; application any; } then { permit; } } }from-zone lab to-zone trust { policy p1 { match { source-address any; destination-address 192.168.0.1; application tcp3389; } then { permit; } } }from-zone desktop to-zone trust { policy p2 { match { source-address any; destination-address any; application any; } then { permit; }...firewall { filter fbf { term 1 { from { source-address { 192.168.0.1/32; } } then { count lab; routing-instance lab; } } term 2 { from { source-address { 0.0.0.0/0; } } then { count desktop; routing-instance desktop; } } }}routing-instances { lab { instance-type virtual-router; interface ge-0/0/1.0; routing-options { static { route 0.0.0.0/0 next-hop 172.27.103.1; } } } desktop { instance-type virtual-router; interface fe-0/0/4.0; routing-options { static { route 0.0.0.0/0 next-hop 173.27.103.1; } ...security { flow { tcp-session { no-syn-check; } } }
Root@SRX210# show
interfaces { ge-0/0/0 { unit 0 { family inet { filter { input fbf; } address 192.168.0.254/24; } } } ge-0/0/1 { unit 0 { family inet { address 172.27.103.42/24; } } } fe-0/0/4 { unit 0 { family inet { address 173.27.103.42/24; } } }}...routing-options { interface-routes { rib-group inet rib1; } rib-groups { rib1 { import-rib [ inet.0 lab.inet.0 desktop.inet.0 ]; } }}policies { from-zone trust to-zone lab { policy p1 { match { source-address any; destination-address any; application any; } then { permit; } } }from-zone lab to-zone trust { policy p1 { match { source-address any; destination-address 192.168.0.1; application tcp3389; } then { permit; } } }from-zone desktop to-zone trust { policy p2 { match { source-address any; destination-address any; application any; } then { permit; }...firewall { filter fbf { term 1 { from { source-address { 192.168.0.1/32; } } then { count lab; routing-instance lab; } } term 2 { from { source-address { 0.0.0.0/0; } } then { count desktop; routing-instance desktop; } } }}routing-instances { lab { instance-type virtual-router; interface ge-0/0/1.0; routing-options { static { route 0.0.0.0/0 next-hop 172.27.103.1; } } } desktop { instance-type virtual-router; interface fe-0/0/4.0; routing-options { static { route 0.0.0.0/0 next-hop 173.27.103.1; } ...security { flow { tcp-session { no-syn-check; } } }
root@srx210# run show security flow session destination-port 23 Session ID: 12732, Policy name: p1/6, Timeout: 4, Valid In: 192.168.0.1/61733 --> 50.50.50.50/23;tcp, If: ge-0/0/0.0, Pkts: 1, Bytes: 52 Out: 50.50.50.50/23 --> 192.168.0.1/61733;tcp, If: ge-0/0/1.0, Pkts: 0, Bytes: 0 Total sessions: 1 root@srx210# run show security flow session source-port 23 Session ID: 12379, Policy name: p1/9, Timeout: 1790, Valid In: 50.50.50.50/23 --> 192.168.0.1/61733;tcp, If: fe-0/0/4.0, Pkts: 4, Bytes: 236 Out: 192.168.0.1/61733 --> 50.50.50.50/23;tcp, If: ge-0/0/0.0, Pkts: 4, Bytes: 190 Total sessions: 1
Root@srx210#run show log flow May 23 07:05:23 07:05:22.977374:CID-0:RT:<50.50.50.50/23->192.168.0.1/61733;6> matched filter b: May 23 07:05:23 07:05:22.977374:CID-0:RT:packet [52] ipid = 1073, @421fcf9e May 23 07:05:23 07:05:22.977374:CID-0:RT:---- flow_process_pkt: (thd 1): flow_ctxt type 13, common flag 0x0, mbuf 0x421fcd80, rtbl_idx = 5 May 23 07:05:23 07:05:22.977374:CID-0:RT: flow process pak fast ifl 69 in_ifp fe-0/0/4.0 <<<<<<<<< return traffic's ingress interface May 23 07:05:23 07:05:22.977374:CID-0:RT: fe-0/0/4.0:50.50.50.50/23->192.168.0.1/61733, tcp, flag 12 syn ack <<<<<<<<< tcp sync ack May 23 07:05:23 07:05:22.977374:CID-0:RT: find flow: table 0x52301870, hash 14992(0xffff), sa 50.50.50.50, da 192.168.0.1, sp 23, dp 61733, proto 6, tok 20486 May 23 07:05:23 07:05:22.977374:CID-0:RT: no session found, start first path. in_tunnel - 0, from_cp_flag - 0 <<<<<<<<< no session matched because the session token is different May 23 07:05:23 07:05:22.977374:CID-0:RT: flow_first_create_session <<<<<<<<< new session created May 23 07:05:23 07:05:22.977374:CID-0:RT: flow_first_in_dst_nat: in <fe-0/0/4.0> , out <N/A> dst_adr 192.168.0.1, sp 23, dp 61733 May 23 07:05:23 07:05:22.977374:CID-0:RT: chose interface fe-0/0/4.0 as incoming nat if. May 23 07:05:23 07:05:22.977374:CID-0:RT:flow_first_rule_dst_xlate: DST no-xlate: 0.0.0.0(0) to 192.168.0.1(61733) May 23 07:05:23 07:05:22.977374:CID-0:RT:flow_first_routing: vr_id 5, call flow_route_lookup(): src_ip 50.50.50.50, x_dst_ip 192.168.0.1, in ifp fe-0/0/4.0, out ifp N/A sp 23, dp 61733, ip_proto 6, tos 0 May 23 07:05:23 07:05:22.977374:CID-0:RT:Doing DESTINATION addr route-lookup May 23 07:05:23 07:05:22.977374:CID-0:RT: routed (x_dst_ip 192.168.0.1) from desktop (fe-0/0/4.0 in 0) to ge-0/0/0.0, Next-hop: 192.168.0.1 May 23 07:05:23 07:05:22.977374:CID-0:RT: policy search from zone desktop-> zone trust (0x0,0x17f125,0xf125) May 23 07:05:23 07:05:22.977374:CID-0:RT: app 0, timeout 1800s, curr ageout 20s May 23 07:05:23 07:05:22.977374:CID-0:RT:flow_first_src_xlate: nat_src_xlated: False, nat_src_xlate_failed: False May 23 07:05:23 07:05:22.977374:CID-0:RT:flow_first_src_xlate: src nat returns status: 0, rule/pool id: 0/0, pst_nat: False. May 23 07:05:23 07:05:22.977374:CID-0:RT: dip id = 0/0, 50.50.50.50/23->50.50.50.50/23 protocol 0 May 23 07:05:23 07:05:22.977374:CID-0:RT: choose interface ge-0/0/0.0 as outgoing phy if May 23 07:05:23 07:05:22.977374:CID-0:RT:is_loop_pak: No loop: on ifp: ge-0/0/0.0, addr: 192.168.0.1, rtt_idx:0 ........