Configuring Default Deny-All and Reject Rules

By default, security devices running Junos OS deny traffic unless rules are explicitly created to allow it using the following command:

You can configure your security devices running Junos OS to enforce the following default reject rules with logging on all network traffic:

  • Invalid fragments

  • Fragmented IP packets that cannot be reassembled completely

  • Where the source address is equal to the address of the network interface

  • Where the source address does not belong to the networks associated with the network interface

  • Where the source address is defined as being on a broadcast network

  • Where the source address is defined as being on a multicast network

  • Where the source address is defined as being a loopback address

  • Where the source address is a multicast packet

  • Where the source or destination address is a link-local address

  • Where the source or destination address is defined as being an address “reserved for future use” as specified in RFC 5735 for IPv4

  • Where the source or destination address is defined as an “unspecified address” or an address “reserved for future definition and use” as specified in RFC 3513 for IPv6

  • With the IP option Loose Source Routing, Strict Source Routing, or Record Route is specified

Note:

You can configure the drop-flow to disable CREATE and CLOSE sessions. Starting in Junos OS Release 23.4R1, Juniper supports a new feature drop-flow to prevent security attacks. You can control and limit the number of max-session for the drop-flow. The session in the drop-flow is valid for 4 seconds by default. During a drop-flow, the session state displays as Drop, but in the flow, the state remains as Valid.

The drop-flow feature is enabled by default. To disable the feature, use the set security flow drop-flow max-sessions 0 command. To delete only the drop-flow feature, use the run clear security flow session drop-flow command.

To view the current drop-flow configuration, use the show security flow drop-flow command, and the view all the available drop-flow, use the show security flow session drop-flow command. For more information, see Flow-Based Sessions.

The following procedure describes drop-flow behaviour when in FIPS mode.

  • With default policy, deny-all configured drop-flow session too will be created.

  • By default drop-flow feature is enabled and RT log will populate only RT_FLOW_SESSION_CREATE entries for dropped session, but max sessions will be 10.

  • To disable drop-flow feature which includes session and RT log, use the following command:

  • To enable drop-flow feature which includes session and RT log having both RT_FLOW_SESSION_CREATE and RT_FLOW_SESSION_CLOSE entries, use the following command: