Verifying A Stateful Firewall Filter - Juniper J2300 User Manual

J-series services router
Hide thumbs Also See for J2300:
Table of Contents

Advertisement

J-series™ Services Router User Guide
Verify that the terms are listed in the order in which you want the packets to be
tested. You can move terms within a firewall filter by using the
For more information, see "Inserting an Identifier" on page 152.

Verifying a Stateful Firewall Filter

Verify the firewall filter configured in "Configuring a Stateful Firewall Filter with a
Purpose
Configuration Editor" on page 393.
To verify that the actions of the firewall filter terms are taken, send packets to and
Action
from the untrusted network that match the terms. In addition, verify that actions
are not taken for packets that do not match.
NOTE: To view the configuration of
junos-defaults applications application-set junos-algs-outbound
command.
Sample Output
user@trusted-nw-trusted-host> ping untrusted-nw-untrusted-host
PING untrusted-nw-untrusted-host.acme.net (172.69.13.5): 56 data bytes
64 bytes from 192.169.13.5: icmp_seq=0 ttl=22 time=8.238 ms
64 bytes from 192.169.13.5: icmp_seq=1 ttl=22 time=9.116 ms
64 bytes from 192.169.13.5: icmp_seq=2 ttl=22 time=10.875 ms
...
420
Verifying Firewall Filter Configuration
Send packets—associated with the
host in the trusted network to a host in the untrusted network. Verify that
packets received from the host in the untrusted network are responses only
to the session originated by the host in the trusted network. To ensure that
packets from the host are not accepted because of rule
send packets to the host in the untrusted network with an IP address that
matches
.
192.168.33.0/24
For example, send a ping request from host
, and verify that a ping response is returned. Ping
untrusted-nw-untrusted-host
requests and responses use ICMP, which belongs to the
application set.
Send packets from a host in the untrusted network to a host in the trusted
network. Verify that the host in the trusted network receives packets only
from the host in the untrusted network with an IP address that matches
.
192.168.33.0/24
For example, send a ping request from host
address that matches
192.168.33.0/24
that a ping response is returned.
Verify that the ping response displays an IP address from the configured
NAT pool.
application set—from a
junos-algs-outbound
from-wan-rule
trusted-nw-trusted-host
junos-algs-outbound
, enter the
junos-algs-outbound
configuration mode
untrusted-nw-trusted-host
to host
trusted-nw-trusted-host
CLI command.
insert
, do not
to host
show groups
with an IP
, and verify

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

J2350J2320J4300J6300J6350J4350

Table of Contents