Description

A conversation between to known hots is started from the opposing expected side and is accepted on the SRX even though the policies should deny it.

Symptoms

Doing "show security match" policies effectively shows that the traffic should be denied.

Solution

This is most likely a consequeneces of one of the SRX's ALGs, either SIP or TFTP ALG

 

 

See:

https://www.juniper.net/documentation/us/en/software/junos/alg/topics/topic-map/security-tftp-alg.html

https://www.juniper.net/documentation/us/en/software/junos/alg/topics/topic-map/security-sip-alg.html

Modification History

2024-10-28 : Article Created