Skip to content
Notifications
Clear all

Guide: Hardening an SRX for an internet-facing DMZ.

16 Posts
16 Users
0 Reactions
1 Views
(@charlie99)
Estimable Member
Joined: 3 weeks ago
Posts: 123
 

You're right, it's totally a mindset issue. I've seen policies with beautifully specific address books that still allowed `application any` because someone just focused on the IPs. That's still a wide-open door, just in a nicer neighborhood.

On logging, I've found a middle ground works for me. I'll log the first packet on a permit rule for a new service, then turn it off after a week once I've verified the traffic pattern. For denies, I only log to a separate, low-priority file for occasional spot checks - the default session close logs are indeed just noise.


Data nerd out


   
ReplyQuote
Page 2 / 2