Configuring Default Deny-All and Reject Rules
By default, security devices running Junos OS deny traffic unless rules are explicitly created to allow it using the following command:
[edit] user@host#set security policies default-policy deny-all
You can configure your security devices running Junos OS to enforce the following default reject rules with logging on all network traffic:
Invalid fragments
Fragmented IP packets that cannot be reassembled completely
Where the source address is equal to the address of the network interface
Where the source address does not belong to the networks associated with the network interface
Where the source address is defined as being on a broadcast network
Where the source address is defined as being on a multicast network
Where the source address is defined as being a loopback address
Where the source address is a multicast packet
Where the source or destination address is a link-local address
Where the source or destination address is defined as being an address “reserved for future use” as specified in RFC 5735 for IPv4
Where the source or destination address is defined as an “unspecified address” or an address “reserved for future definition and use” as specified in RFC 3513 for IPv6
With the IP option Loose Source Routing, Strict Source Routing, or Record Route is specified
You can configure the drop-flow to disable CREATE and CLOSE sessions. Starting in Junos OS Release 23.4R1, Juniper supports a new feature drop-flow to prevent security attacks. You can control and limit the number of max-session for the drop-flow. The session in the drop-flow is valid for 4 seconds by default. During a drop-flow, the session state displays as Drop, but in the flow, the state remains as Valid.
The drop-flow feature is enabled by default. To disable the feature, use the set security flow drop-flow max-sessions 0 command. To delete only the drop-flow feature, use the run clear security flow session drop-flow command.
To view the current drop-flow configuration, use the show security flow drop-flow command, and the view all the available drop-flow, use the show security flow session drop-flow command. For more information, see Flow-Based Sessions.
The following procedure describes drop-flow behaviour when in FIPS mode.
-
With default policy, deny-all configured drop-flow session too will be created.
-
By default drop-flow feature is enabled and RT log will populate only RT_FLOW_SESSION_CREATE entries for dropped session, but max sessions will be 10.
-
To disable drop-flow feature which includes session and RT log, use the following command:
host@srx#set security flow drop-flow max-sessions 0
-
To enable drop-flow feature which includes session and RT log having both RT_FLOW_SESSION_CREATE and RT_FLOW_SESSION_CLOSE entries, use the following command:
host@srx# set security flow drop-flow max-sessions
Possible completions: <max-sessions> Maximum Drop-flow Sessions (default 10%) (0..30 percent) [edit] host@srx#