In transparent mode, security policies can be configured only between Layer 2 zones. When packets are forwarded through the bridge domain, the security policies are applied between security zones. A security policy for transparent mode is similar to a policy configured for Layer 3 zones, with the following exceptions:
Layer 2 forwarding does not permit any interzone traffic unless there is a policy explicitly configured on the device. By default, Layer 2 forwarding performs the following actions:
This default behavior can be changed for bridge packet flow by using either J-Web or the CLI configuration editor:
![]() |
Note: You cannot configure both options at the same time. |
For more information about security policies, see JUNOS Software Security Configuration Guide.