Posts

Showing posts with the label juniper srx ping block

Block ICMP on Juniper SRX 210

Assume you have SRX connected to a VLAN, example 192.168.1.0/24. SRX has IP in that subnet, like 192.1168.1.1. You have PCs in that same VLAN/subnet and try to block ICMP between those PCs, so you want to effectively block 192.168.1.5 from pinging 192.168.1.6. So is it possible on SRX 210? Well, you may think that it should be done with some polices like: match source address my PC match application [junos-ping, junos-icmp-all.....] match destiantion address any then reject > The result of this policy - you won't be able to ping external hosts (public IPs) but you can ping your local hosts in vlan. This can not be accomplished via policies btw since the PCs are in the same vlan. Another posibility is to apply firewall filter into vlan confiuration: set firewall family inet filter icmp term 1 from protocol icmp set firewall family inet filter icmp term 1 then discard set firewall family inet filter icmp term 2 then accept set interfaces vlan unit 2 family inet filter input icmp...