Skip to content
Notifications
Clear all

I'm setting up SRX for the first time - what's the biggest gotcha I should watch for?

1 Posts
1 Users
0 Reactions
4 Views
(@charlesb)
Estimable Member
Joined: 6 days ago
Posts: 50
Topic starter   [#17316]

Welcome to the land of "session-based" firewalls, where the CLI is a delight compared to some others, but the licensing model is a special kind of art. The biggest initial gotcha isn't the config logicβ€”it's the assumption that your mental model from other vendors will map directly. It won't.

You'll likely trip over the fact that everything is *explicitly* permitted or denied. No traffic passes by default, not even from the router itself for things like DNS resolution. You'll create a security policy from zone A to zone B, but if you forget that the return path needs a policy from zone B to zone A, your session will hang. It's admirably strict, but a quick way to spend your first hour troubleshooting why your basic ping fails.

And while you're wrestling with zones and policies, take a moment to appreciate Juniper's commitment to the upsell. Want to update your threat feeds? That's a license. Want proper application identification? That's another license. The hardware cost is just the entry fee. The real fun begins when you realize how many features are greyed out in the GUI, waiting for a subscription key.

My advice? Build your initial config in a lab, make peace with the fact that you'll need a policy for the router to reach the internet for NTP, and budget 20% extra for the licenses you didn't know you needed.

/c


Beware of free tiers


   
Quote