Configuring The Session Close Notification Rule; Comments For Firewall Rules - Juniper NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Comments for Firewall Rules

Copyright © 2010, Juniper Networks, Inc.
threshold is exceeded, the packet is dropped. A new session can be created only when
the session counts drop below the threshold when existing sessions are aged out.

Configuring the Session Close Notification Rule

An idle TCP connection remains established until terminated by either the client or the
server. If, for any reason, the client or an intermediate device shuts down, the server
continues to wait on the connection. As an intermediate security device, a device running
ScreenOS maintains a session for each TCP connection until it times out. Traffic can
resume if a client sends an RST (reset) packet, but the client needs to be informed of
the situation in order to do so. If the TCP keep-alive option is activated on the server, it
can be used to query the status of the connection.
NSM offers the option of configuring the SSG Series Secure Services Gateways, ISG
Series Integrated Security Gateways, and the NetScreen Series Security Systems running
ScreenOS 6.3 and later to send a notification to both the client and the server when a
TCP session is closed. By default, this option is disabled. Before you can enable the
Session Close Notification feature on NSM for a device, you must first set the following
options:
a. From
>
Device
Advanced
Disable
Skip TCP sequence number check.
Enable one or both of these options:
Check TCP SYN bit before create/refresh session after TCP handshake
Check TCP SYN bit before Create session
Set the number of seconds in the option
b. From
>
Device
Network
Configuring the Session Close Notification option:
Select
>
1.
Policy Manager
. A
Notification
Session Close Notification
Check the option –
2.
Notify both ends if TCP session isn't normally terminated
Click
.
OK
3.
configure the Session Close Notification option by selecting
>
>
Policy
Policy on device
The Comments column of a rule contains the rule title, which is also the ScreenOS policy
name (the name of the policy when viewing the device configuration using the WebUI).
You can also enter comments in the Comment Field, if desired.
>
>:
Packet flow
Notify threshold.
>
, enable
Edit the From / To Zone
>
Security Policy
Policy on device
window opens.
>
Rule Options
Configure All Options Session Close Notification
Chapter 9: Configuring Security Policies
.
TCP/RST
>
>
Rule Options
Session Close
.
Policy Manager
>
Security
.
465

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.4

Table of Contents