Security Policies
Security policies define the rules that control transit traffic—that is, traffic passing through the firewall from one security zone to another.
Policy Configuration Synchronization Behavior
SRX4700 Firewalls with policy configuration synchronization support the
lookup-intact-on-commit option and file serialization.
Feed Server Configuration
feed-server name {
(hostname hostname | url url);
description description;
feed-name name {
description description;
hold-interval seconds;
path path;
update-interval seconds;
}
hold-interval seconds;
password password;
tls-profile tls-profile;
update-interval seconds;
user-name user-name;
validate-certificate-attributes {
subject-or-subject-alternative-names;
}
}|
Feed Server Support |
Supported Numbers |
|---|---|
|
Maximum number of feed servers |
5000 |
|
Maximum number of feeds |
5000 |
|
Maximum number of dynamic addresses entries |
5000 |
Policy Object
set security policies from-zone trust to-zone untrust policy permit-all match source-address any set security policies from-zone trust to-zone untrust policy permit-all match destination-address any set security policies from-zone trust to-zone untrust policy permit-all match application any set security policies from-zone trust to-zone untrust policy permit-all then permit commit
|
Policy Object Type |
Supported Numbers |
|---|---|
|
Address objects per policy |
16384 |
|
Max applications per policy |
3072 |
|
Security policies |
100000 |
|
Policy contexts (zone pairs) |
8192 |
|
Policies per context |
100000 |
|
Policies with counting enabled |
1024 |