Reorder a Security Policy Rule
Security policies apply security policy rules to the network traffic within a context, such as the from-zone to the to-zone. The network traffic is classified by matching the security policy rules characteristics.
The action of the first security policy rule that matches the traffic is applied to the packet. If there are no matching rules, the packet is dropped. The rules are matched in an ascending order, so you must place specific policy rules at the top of general policy rules in the security policy rules list.
For example, consider a security policy P1 on device D1.
-
The security policy operates from the untrust zone to the trust zone with two rules—Rule-a and Rule-b.
-
When you move Rule-a to the bottom of the policy rules list, Juniper Security Director Cloud automatically moves Rule-b to the first place on the device D1.

To reorder a security policy rule: