show security alg status
Syntax
show security alg status
Description
This command displays the status (enabled/disabled) of the supported Application Layer Gateway (ALG) transactions.
The following list describes the default status on each of these devices:
On all SRX Series Firewalls — The RSH, SQL, and IKE-ESP ALGs are disabled by default.
SRX1500, SRX4100, SRX4200, SRX5400, SRX5600, and SRX5800 devices—FTP, TFTP, DNS, MS-RPC, PPTP, SUNRPC, and TALK ALGs are enabled by default. All other ALGs are disabled.
SRX300, SRX320, SRX340, and SRX380 devices—All supported ALGs except the IKE-ESP, RSH, SQL, and TWAMP ALGs are enabled by default.
Options
node—Display the ALG status on a specific node.
logical-system—Display the ALG configuration status for a specific logical system.
root-logical-system—Display the default ALG configuration status for a root logical system.
Required Privilege Level
view
Output Fields
The
following list describes the output fields for the show security
alg status
command. Output fields are listed in the approximate
order in which they appear.
DNS—
Domain Name ServerFTP—
File Transfer ProtocolH323—
H.323 protocolMGCP—
Media Gateway Control ProtocolMSRPC—
Microsoft remote procedure callPPTP—
Point-to-Point Tunneling ProtocolRSH—
UNIX remote shell servicesRTSP—
Real-Time Streaming ProtocolSCCP—
Skinny Client Control ProtocolSIP—
Session Initiation ProtocolSQL—
Oracle SQLSUNRPC—
Sun Microsystems remote procedure callTALK—
TALK programTFTP—
Trivial File Transfer ProtocolIKE-ESP—nat—
Internet Key Exchange and Encapsulating Security Payload. Configure IKE-ESP ALG with NATTWAMP—
Two-Way Active Measurement Protocol
Sample Output
- ALG status
- ALG status for a specific logical system
- ALG status for all logical systems including root logical system
- ALG status for a specific tenant system
- ALG status for all tenant systems
- ALG status for all logical systems and tenant systems
ALG status
user@host> show security alg status DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Disabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled
ALG status for a specific logical system
user@host> show security alg status logical-system LSYS1 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled
ALG status for all logical systems including root logical system
user@host> show security alg status logical-system all Logical system: root-logical-system ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled Logical system: LSYS3 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled Logical system: LSYS1 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled Logical system: LSYS2 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled Logical system: LSYS0 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Disabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled
ALG status for a specific tenant system
user@host> show security alg status tenant TN1 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Enabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled
ALG status for all tenant systems
user@host> show security alg status tenant all Tenant : TN1 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Enabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled Tenant : TN2 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Enabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled
ALG status for all logical systems and tenant systems
user@host> show security alg status all-logical-systems-tenants Logical system : root-logical-system ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Disabled SCCP : Disabled SIP : Disabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled Logical system : LSYS1 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Enabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled Tenant : TN1 ALG Status: DNS : Enabled FTP : Enabled H323 : Disabled MGCP : Disabled MSRPC : Enabled PPTP : Enabled RSH : Disabled RTSP : Enabled SCCP : Disabled SIP : Enabled SQL : Disabled SUNRPC : Enabled TALK : Enabled TFTP : Enabled IKE-ESP : Disabled TWAMP : Disabled
Release Information
Command modified in Junos OS Release 9.5.
Command output is modified to display the details for the TWMAP ALG in Junos OS Release 18.2.