The following tables list security features that are supported on SRX 3400, SRX 3600, SRX 5600, and SRX 5800 services gateways.
Table 21: Zones
Feature |
More Information |
|---|---|
Security zone |
|
Functional zone |
|
For information about the interfaces that are supported on your device, see the JUNOS Software Interfaces and Routing Configuration Guide. |
|
Table 22: Flow
Feature |
More Information |
|---|---|
Combo-mode support (SRX 3400 and SRX 3600 only) |
|
Flow-based processing (SRX 3400 and SRX 3600 only) |
Table 23: Security Policy
Feature |
More Information |
|---|---|
Address books |
|
Policy application sets |
|
Schedulers |
|
Policy applications |
Understanding Internet-Related Predefined Policy Applications |
Internet Control Message Protocol (ICMP) predefined policy application |
|
Internet-related predefined policy applications |
Understanding Internet-Related Predefined Policy Applications |
Microsoft predefined policy applications |
|
Dynamic routing protocols predefined policy applications |
Understanding Dynamic Routing Protocols Predefined Policy Applications |
Streaming video predefined policy applications |
Understanding Streaming Video Predefined Policy Applications |
Sun remote procedure protocol (RPC) predefined policy applications |
|
Security and tunnel predefined policy applications |
Understanding Security and Tunnel Predefined Policy Applications |
IP-related predefined policy applications |
|
Instant messaging predefined policy applications |
Understanding Instant Messaging Predefined Policy Applications |
Management predefined policy applications |
|
Mail predefined policy applications |
|
UNIX predefined policy applications |
|
Miscellaneous predefined policy applications |
|
Custom policy Applications |
|
Policy application timeouts |
|
Policy verification (SRX 5600 and SRX 5800 only) |
Table 24: Firewall Authentication
Feature |
More Information |
|---|---|
Web authentication |
|
Pass-through authentication |
|
Local authentication server |
|
RADIUS authentication server |
|
LDAP authentication server |
|
SecurID authentication server |
Table 25: Infranet Authentication
Feature |
More Information |
|---|---|
JUNOS Enforcers in Unified Access Control (UAC) deployments |
Table 26: Attack Detection and Prevention
Feature |
More Information |
|---|---|
Bad IP option |
|
Block fragment traffic |
|
FIN flag without ACK flag set protection |
|
ICMP flood protection |
|
ICMP fragment protection |
|
Large size ICMP packet protection |
|
Loose source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP record route option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP security option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP address spoof |
|
IP stream option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP strict source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP address sweep |
|
IP timestamp option |
Screen Options for Detecting IP Options Used For Reconnaissance |
Land attack protection |
|
Ping of death attack protection |
|
Port scan |
|
Source IP based session limit |
|
SYN-ACK-ACK proxy protection |
|
SYN and FIN flags set protection |
|
SYN flood protection |
|
SYN fragment protection |
|
Teardrop attack protection |
|
TCP packet without flag set protection |
|
Unknown protocol protection |
|
UDP flood protection |
|
WinNuke attack protection |
Table 27: Network Address Translation
Table 28: Chassis Cluster
Table 29: IPsec
Table 30: PKI
Table 31: ALGs
Table 32: IDP Policy
Feature |
More Information |
|---|---|
Intrusion Detection and Prevention (IDP) Policy |
|
Intrusion prevention system (IPS) rulebase |
|
Exempt rulebase |
|
Custom attacks |
|
Differentiated Services code point (DSCP) marking |
Table 33: IDP Signature Database
Feature |
More Information |
|---|---|
IDP signature database |
|
Predefined policy templates |
|
Signature database—manual download |
|
Signature database—automatic download |
|
Signature database version |
Table 34: IDP Application Identification
Feature |
More Information |
|---|---|
Application identification |
|
Service and application bindings |
|
Application system cache |
Table 35: IDP Monitoring and Logging
Feature |
More Information |
|---|---|
IDP logging |
|
IDP monitoring and debugging (SRX 3400 and SRX 3600 only) |
JUNOS Software CLI Reference |
Table 36: IDP SSL Inspectioon
Feature |
More Information |
|---|---|
IDP SSL Inspection |