srx secrets

9
SRX Secrets Michel Tepper

Upload: ivory

Post on 07-Jan-2016

83 views

Category:

Documents


3 download

DESCRIPTION

SRX Secrets. Michel Tepper. SRX. Agenda Security Routing Switching. SRX. Security Sure: statefull firewalling IPSEC But what about Screening options IDP App secure UAC integration? root@FW-SRX550# ... es from-zone guest to-zone untrust policy p1 match source-identity ? - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: SRX Secrets

SRX Secrets

Michel Tepper

Page 2: SRX Secrets

SRX

Agenda

•Security•Routing•Switching

Page 3: SRX Secrets

SRXSecurity-Sure: statefull firewalling

IPSEC

-But what about

Screening options

IDP

App secure

UAC integration?

root@FW-SRX550# ...es from-zone guest to-zone untrust policy p1 match source-identity ?

Possible completions:

<source-identity-name> Specify source-identity name from list to match

[ Open a set of values

any Any user includes authenticated, unauthenticated and unknown user

authenticated-user All authenticated users

unauthenticated-user All unauthenticated users

unknown-user All unknown users

Page 4: SRX Secrets

SRX

Routing- Static, of course- OSPF- BGP- ISIS- MPLS / VPLS- BFD

Who knows the statement:

set security forwarding-options family mpls mode packet-based ?

Page 5: SRX Secrets

SRX

Routing

Route based VPN’s

Not realy a secret anymore

But: very often static routing is used

OSPF offers great redudancy

Add BFD and failover occurs within a second.

Page 6: SRX Secrets

SRX

Routing

Selective packet based

What if some traffic needs to by-pass the flow module?.

Example: backup traffic

Use a packet filter to create an exception!

Page 7: SRX Secrets

SRX

Routing

Stateless firewall rules

Very usefull, even on a statefull device-Drop traffic before it hits the flow module-Class Of Service -Rate limiting

Page 8: SRX Secrets

SRX

Switching

-Switching-LAG interfaces !!-POE

-Also in SMB cluster-IN DataCentre with VRRP

Page 9: SRX Secrets

SRX

Thank you!