TCP Optimization on Firewalls
By explicitly enabling TCP Proxy through security policies, you gain precise control over session behavior, optimizing TCP parameters such as congestion control, buffer management, and selective acknowledgment settings.
The system engages the Flow TCP Proxy module for sessions that may require TCP Proxy. Currently, this process occurs implicitly, and you cannot control which sessions use TCP Proxy. In addition, when TCP Proxy is enabled, you cannot configure any parameters. All TCP Proxy parameters are global and cannot be modified.
This feature enables the SRX Firewalls to operate solely as a TCP Proxy. It also provides options to configure TCP parameters.
To configure the TCP proxy profile, use the set security flow tcp-proxy tcp-profile
<tcp-profile-name> command. To configure security policy with default (global
TCP Profile), use the set security policies from-zone <src zone> to-zone
<dst-zone> policy <policy-name> then permit tcp-proxy command.
When you configure security policies to leverage the TCP Proxy, use the specific CLI
commands to associate TCP Profiles with policies. Set rules that specify whether TCP Proxy is
applied to the client-side, server-side, or both. For example, use the command set
security policies from-zone trust to-zone untrust policy p1 then permit tcp-proxy
client-profile mobile-tcp to explicitly define TCP Proxy settings for sessions
originating from a trusted zone to an untrusted zone. Additionally, use show security
policies detail to verify the TCP Proxy configurations within your policies,
ensuring that the correct profiles and parameters are applied.
Benefits of TCP Proxy
-
Gain greater control over TCP session parameters, to tailor configurations for specific network conditions and improve network efficiency.
-
Manage Transmission Control Protocol (TCP) sessions by explicitly configuring security policies. This approach allows precise adjustments to buffer management and congestion control parameters.