Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

show security dynamic-policies

Syntax

Description

Display dynamic policies downloaded on the group member. This command is supported on SRX100, SRX110, SRX210, SRX220, SRX240, and SRX650 devices.

Options

  • none—Display basic information about all policies installed on the group member.

  • detail—(Optional) Display a detailed view of all of the policies installed on the group member.

  • from-zone—(Optional) Display information about the policies installed on the group member for the specified source zone.

  • scope-id—(Optional) Display information about the policies installed on the group member for the specified policy identifier.

  • to-zone—(Optional) Display information about the policies installed on the group member for the specified destination zone.

Required Privilege Level

view

Output Fields

Table 1 lists the output fields for the show security dynamic-policies command. Output fields are listed in the approximate order in which they appear.

Table 1: show security dynamic-policies Output Fields

Field Name

Field Description

Policy

Name of the applicable Policy.

State

Status of the policy:

  • enabled: The policy can be used in the policy lookup process, which determines access rights for a packet and the action taken in regard to it.

  • disabled: The policy cannot be used in the policy lookup process, and therefore it is not available for access control.

Index

An internal number associated with the policy.

Scope Policy

Policy identifier.

Sequence number

Number of the policy within a given context. For example, three policies that are applicable in a from-zoneA-to-zoneB context might be ordered with sequence numbers 1, 2, and 3. Also, in a from-zoneC-to-zoneD context, four policies might have sequence numbers 1, 2, 3, and 4.

Source addresses

For standard display mode, the names of the source addresses for a policy. Address sets are resolved to their individual names. (In this case, only the names are given, not their IP addresses.)

For detail display mode, the names and corresponding IP addresses of the source addresses for a policy. Address sets are resolved to their individual address name-IP address pairs.

Destination addresses

Name of the destination address (or address set) as it was entered in the destination zone’s address book. A packet’s destination address must match this value for the policy to apply to it.

Application

Name of a preconfigured or custom application whose type the packet matches, as specified at configuration time.

  • IP protocol: The IP protocol used by the application—for example, TCP, UDP, ICMP.

  • ALG: If an ALG is associated with the session, the name of the ALG. Otherwise, 0.

  • Inactivity timeout: Elapse time without activity after which the application is terminated.

  • Source port range: The low-high source port range for the session application.

  • Destination port range: The low-high destination port range for the session application.

action-type

Must be permit.

Policy Type

Must be dynamic.

From zone

Name of the source zone.

To zone

Name of the destination zone.

Tunnel

Tunnel name, type (IPsec), and index number.

Sample Output

show security dynamic-policies

Sample Output

show security dynamic-policies detail

Sample Output

show security dynamic-policies from-zone Internal

Sample Output

show security dynamic-policies scope-id 8 from-zone Internal

Sample Output

show security dynamic-policies detail from-zone Internal

Sample Output

show security dynamic-policies detail from-zone Internal to-zone Host

Release Information

Command introduced in Junos OS Release 10.2.