The following tables list security features that are supported on SRX 210 and SRX 240 services gateways.
Table 4: Zones
Feature |
More Information |
|---|---|
Security zone |
|
Functional zone |
|
For information about the interfaces that are supported on your device, see the JUNOS Software Interfaces and Routing Configuration Guide. |
|
Table 5: Flow
Feature |
More Information |
|---|---|
Flow-based processing |
Table 6: Security Policy
Feature |
More Information |
|---|---|
Address books |
|
Policy application sets |
|
Schedulers |
|
Policy applications |
Understanding Internet-Related Predefined Policy Applications |
Internet Control Message Protocol (ICMP) predefined policy application |
|
Internet-related predefined policy applications |
Understanding Internet-Related Predefined Policy Applications |
Microsoft predefined policy applications |
|
Dynamic routing protocols predefined policy applications |
Understanding Dynamic Routing Protocols Predefined Policy Applications |
Streaming video predefined policy applications |
Understanding Streaming Video Predefined Policy Applications |
Sun remote procedure protocol (RPC) predefined policy applications |
|
Security and tunnel predefined policy applications |
Understanding Security and Tunnel Predefined Policy Applications |
IP-related predefined policy applications |
|
Instant messaging predefined policy applications |
Understanding Instant Messaging Predefined Policy Applications |
Management predefined policy applications |
|
Mail predefined policy applications |
|
UNIX predefined policy applications |
|
Miscellaneous predefined policy applications |
|
Custom policy applications |
|
Policy application timeouts |
Table 7: Firewall Authentication
Feature |
More Information |
|---|---|
Web authentication |
|
Pass-through authentication |
|
Local authentication server |
|
RADIUS authentication server |
|
LDAP authentication server |
|
SecurID authentication server |
Table 8: Attack Detection and Prevention
Feature |
More Information |
|---|---|
Bad IP option |
|
Block fragment traffic |
|
FIN flag without ACK flag set protection |
|
ICMP flood protection |
|
ICMP fragment protection |
|
Large size ICMP packet protection |
|
Loose source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP record route option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP security option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP address spoof |
|
IP stream option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP strict source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP address sweep |
|
IP timestamp option |
Screen Options for Detecting IP Options Used For Reconnaissance |
Land attack protection |
|
Ping of death attack protection |
|
Port scan |
|
Source IP based session limit |
|
SYN-ACK-ACK proxy protection |
|
SYN and FIN flags set protection |
|
SYN flood protection |
|
SYN fragment protection |
|
Teardrop attack protection |
|
TCP packet without flag set protection |
|
Unknown protocol protection |
|
UDP flood protection |
|
WinNuke attack protection |
Table 9: Network Address Translation
The following table applies only to the SRX 210 services gateway.
Table 10: Chassis Cluster
The following table applies only to the SRX 210 services gateway.
Table 11: ALGs
Feature |
More Information |
|---|---|
FTP Application Layer Gateway (ALG) |
|
Trivial File Transfer Protocol (TFTP) ALG |
The following table applies only to the SRX 210 services gateway.
Table 12: IPsec
The following table applies only to the SRX 210 services gateway.
Table 13: PKI