Description

This KB describes the behavior of active sessions when modifying a security policy.

Symptoms

Modifying a security policy that has active sessions.

Solution

The default behavior is that active sessions will not be affected when making modifications.

 

However, if policy-rematch is configured, then the active session will be reevaluated against the new parameters in the policy, which could result in the session getting closed:

 

Enable the device to reevaluate an active session when its associated security policy is modified. The session remains open if it still matches the policy that allowed the session initially.

 

policy-rematch

https://www.juniper.net/documentation/us/en/software/junos/security-policies/topics/ref/statement/security-edit-policy-rematch.html

 

Another exception is if the policy is renamed as stated in KB28413 [juniper.net]:

 

[SRX] Renaming a policy closes sessions associated with the policy

https://supportportal.juniper.net/s/article/SRX-Renaming-a-policy-closes-sessions-associated-with-the-policy?language=en_US

Modification History

2023-10-12 : Article Created
2023-12-19 : Changed to public