Linux, FreeBSD, Juniper, Cisco / Network security articles and troubleshooting guides

FAQ
It is currently Tue Jun 06, 2023 7:42 am


Author Message
mandrei99
Post  Post subject: Juniper SRX IPv6 forwarding - flow mode or packet mode.  |  Posted: Thu Jan 15, 2015 6:13 am

Joined: Tue Aug 04, 2009 9:16 am
Posts: 250

Offline
 

Juniper SRX IPv6 forwarding - flow mode or packet mode.

Default to Junos 11.4, 12.1X44, 12.1X45/46 and 47 for Juniper SRX firewalls is to drop Native ipv6 packets because flow mode for IPv6 is set to "drop". SRX can be configured to either forward IPv6 traffic in "flow" mode (stateful firewall) or "packet" mode (stateless - router behavior).

As with ipv4 traffic, SRX can act as stateful or stateless firewall mode: Meaning both packet mode and flow mode Ipv6 can be configured.

Checking ipv6 forwarding mode on SRX


Code:
root@srx-host> show security flow status
node0:
--------------------------------------------------------------------------
  Flow forwarding mode:
    Inet forwarding mode: flow based
    Inet6 forwarding mode: drop
    MPLS forwarding mode: drop
    ISO forwarding mode: drop
    Advanced services data-plane memory mode: Default
  Flow trace status
    Flow tracing status: on
    Flow tracing options: basic
  Flow session distribution
    Distribution mode: RR-based
  Flow ipsec performance acceleration: off
  Flow packet ordering
    Ordering mode: Hardware

Default forwarding mode is "drop".

Enable IPv6 flow mode in srx:


Code:
root@srx-host# set security forwarding-options family inet6 mode ?
Possible completions:
  drop                 Disable forwarding
  flow-based           Enable flow-based forwarding
  packet-based         Enable packet-based forwarding
root@srx-host# set security forwarding-options family inet6 mode flow-based     
[edit]
root@srx-host# commit and-quit
warning: You have changed inet flow mode.
warning: You must reboot the system for your change to take effect.
If you have deployed a cluster, be sure to reboot all nodes.
warning: You have enabled/disabled inet6 flow.
You must reboot the system for your change to take effect.
If you have deployed a cluster, be sure to reboot all nodes.
commit complete
Exiting configuration mode

root@srx-host> request system reboot
Reboot the system ? [yes,no] (no) yes

Shutdown NOW!
[pid 2882]


After reboot, confirm the forwarding mode for ipv6:
Code:
root@srx-host> show security flow status     

  Flow forwarding mode:
    Inet forwarding mode: flow based
    Inet6 forwarding mode: flow based
    MPLS forwarding mode: drop
    ISO forwarding mode: drop
    Advanced services data-plane memory mode: Default
  Flow trace status
    Flow tracing status: on
    Flow tracing options: basic
  Flow session distribution
    Distribution mode: RR-based
  Flow ipsec performance acceleration: off
  Flow packet ordering
    Ordering mode: Hardware

Confirm IPv6 flows exist on SRX flow table


Junos refers to IPv6 traffic as inet6 family and all commands that differentiate between IPv4 and IPv6 use this family.
Code:
> show security flow session family inet6           
Session ID: 6044, Policy name: self-traffic-policy/1, Timeout: 58, Valid
  In: fe80::fac0:100:d2:3580/1 --> ff02::5/1;ospf, If: gr-0/0/0.0, Pkts: 28282, Bytes: 2149432
  Out: ff02::5/1 --> fe80::fac0:100:d2:3580/1;ospf, If: .local..0, Pkts: 0, Bytes: 0
Total sessions: 1





Top
Display posts from previous:  Sort by  
E-mail friendPrint view

Topics related to - "Juniper SRX IPv6 forwarding - flow mode or packet mode."
 Topics   Author   Replies   Views   Last post 
There are no new unread posts for this topic. Juniper SRX Packet mode - how to switch between flow mode and packet mode

mandrei99

0

10401

Thu Jan 15, 2015 6:36 am

mandrei99 View the latest post

There are no new unread posts for this topic. How to monitor CPU usage and flow sessions via SNMP - Juniper SRX Branch - 12.1X44

mandrei99

0

14374

Tue Jun 18, 2013 6:13 pm

mandrei99 View the latest post

There are no new unread posts for this topic. SRX: How to list firewall flow sessions table

mandrei99

0

11287

Tue Mar 10, 2015 6:08 pm

mandrei99 View the latest post

There are no new unread posts for this topic. Juniper SRX - How to collect RSI (Request Support Information) to provide it to Juniper TAC

mandrei99

0

27960

Fri Jul 12, 2013 9:46 am

mandrei99 View the latest post

There are no new unread posts for this topic. Juniper SRX: How to access/vty on the PFE from CLI

mandrei99

0

8651

Mon Jan 26, 2015 6:39 am

mandrei99 View the latest post

There are no new unread posts for this topic. Juniper SRX cluster - How the hostname is configured

mandrei99

0

6128

Sat Jan 31, 2015 7:04 pm

mandrei99 View the latest post

There are no new unread posts for this topic. Juniper SRX PPPoE configuration for RCS RDS provider in Romania

mandrei99

0

4314

Fri Jan 09, 2015 8:21 am

mandrei99 View the latest post

There are no new unread posts for this topic. Attachment(s) Squid http(s) transparent proxy with Juniper SRX | part 1

mandrei99

0

10465

Fri May 03, 2013 4:30 pm

mandrei99 View the latest post

There are no new unread posts for this topic. Squid http(s) transparent proxy with Juniper SRX | part 2

mandrei99

0

9096

Tue May 21, 2013 5:58 am

mandrei99 View the latest post

There are no new unread posts for this topic. Attachment(s) Squid http(s) transparent proxy with Juniper SRX | part 3

mandrei99

0

8965

Fri May 24, 2013 8:32 am

mandrei99 View the latest post

 

Who is online
Users browsing this forum: No registered users and 1 guest
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
News News Site map Site map SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list


Delete all board cookies | The team | All times are UTC - 5 hours [ DST ]



phpBB SEO