Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

show security policies information

 

Syntax

Release Information

Command introduced in Junos OS Release 18.4R1.

Description

Displays detailed information about the security policies configured on the device.

Note

Dynamic policy counters are only supported in the root logical system.

Options

logical-systemDisplays detailed information about the security policies configured on a logical system or on all logical systems.
root-logical-systemDisplays detailed information about the security policies configured on the root logical system. This is the default option.
tenantDisplays detailed information about the security policies configured on a tenant.

Required Privilege Level

view

List of Sample Output

show security policies information

show security policies information logical-system all

Output Fields

Table 1 lists the output fields for the show security policies information command. Output fields are listed in the approximate order in which they appear.

Table 1: show security policies Output Fields

Field Name

Field Description

Number of global policies

Number of global policies configured on the device.

Number of policies with scheduler

Number of policies with schedulers configured on the device.

Number of policies with statistics enabled

Number of policies configured with statistics enabled on the device and the maximum number of policies which can be configured with statistics enabled on the device.

Number of unified policies

Number of unified policies configured on the device.

Number of policy contexts

Number of policy contexts configured on the device.

Number of Policies per context

Number of policies per context configured on the device and the maximum number of policies per context that can be configured on the device.

Number of Source addresses per policy

Number of source addresses configured per policy and the maximum number of source addresses configured per policy.

The source address in the match criteria is composed of one or more address names or address set names in the from-zone.

Number of Destination addresses per policy

Number of destination addresses configured per policy and maximum of destination addresses that can be configured per policy.

The destination address of the match criteria is composed of one or more address names or address set names in the to-zone.

Number of Applications per policy

Number of applications per policy and the maximum number of applications per policy.

Number of Dynamic applications per policy

Number of dynamic applications per policy and the maximum number of dynamic applications per policy.

Number of Source identities per policy

Number of source identities per policy and the maximum number of source identities per policy.

Messages received

Number of messages received.

Messages rejected

Number of messages rejected.

Add messages received

Number of add messages received.

Delete messages received

Number of delete messages received.

Clear messages received

Number of clear messages received.

Invalid messages received

Number of invalid messages received.

Add messages sent to PFE

Number of add messages sent from Routing Engine to Packet Forwarding Engine.

Delete messages sent to PFE

Number of delete messages sent from Routing Engine to Packet Forwarding Engine.

Clear messages sent to PFE

Number of clear messages sent from Routing Engine to Packet Forwarding Engine.

Policy added successfully

Number of policies successfully added.

Policy deleted successfully

Number of policies successfully deleted.

Policy cleared successfully

Number of policies successfully cleared.

Policy add failures

Number of policies unsuccessfully added.

Policy delete failures

Number of policies unsuccessfully deleted.

Policy clear failures

Number of policies unsuccessfully cleared.

SSAM send attempted

Number of SSAM message attempts sent to Internet Key Exchange Protocol Daemon (IKED).

SSAM send succeeded

Number of SSAM messages sent to IKED.

SSAM send failed

Number of SSAM messages unsucessfully sent to IKED.

Policy failures - bad configuration

Number of messages with invalid dynamic policy configurations provided.

Policy failures - bad scope policy

Number of messages with invalid scope policy provided.

Dependent-dynamic-application-lookup

Value of the unified policy dependent match flag’s value (Dependent-dynamic-application-lookup).

Unified-policy-implicit-match

Value of the unified policy implicit match flag’s value (Unified-policy-implicit-match).

Sample Output

show security policies information

user@host> show security policies information

show security policies information logical-system all

user@host> show security policies information logical-system all