Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

show security alg status

date_range 19-Nov-23

Syntax

content_copy zoom_out_map
show security alg status

Description

This command displays the status (enabled/disabled) of the supported Application Layer Gateway (ALG) transactions.

The following list describes the default status on each of these devices:

  • On all SRX Series Firewalls — The RSH, SQL, and IKE-ESP ALGs are disabled by default.

  • SRX1500, SRX4100, SRX4200, SRX5400, SRX5600, and SRX5800 devices—FTP, TFTP, DNS, MS-RPC, PPTP, SUNRPC, and TALK ALGs are enabled by default. All other ALGs are disabled.

  • SRX300, SRX320, SRX340, and SRX380 devices—All supported ALGs except the IKE-ESP, RSH, SQL, and TWAMP ALGs are enabled by default.

Options

  • node—Display the ALG status on a specific node.

  • logical-system—Display the ALG configuration status for a specific logical system.

  • root-logical-system—Display the default ALG configuration status for a root logical system.

Required Privilege Level

view

Output Fields

The following list describes the output fields for the show security alg status command. Output fields are listed in the approximate order in which they appear.

  • DNS—Domain Name Server

  • FTP—File Transfer Protocol

  • H323—H.323 protocol

  • MGCP—Media Gateway Control Protocol

  • MSRPC—Microsoft remote procedure call

  • PPTP—Point-to-Point Tunneling Protocol

  • RSH—UNIX remote shell services

  • RTSP—Real-Time Streaming Protocol

  • SCCP—Skinny Client Control Protocol

  • SIP—Session Initiation Protocol

  • SQL—Oracle SQL

  • SUNRPC—Sun Microsystems remote procedure call

  • TALK—TALK program

  • TFTP—Trivial File Transfer Protocol

  • IKE-ESP—nat—Internet Key Exchange and Encapsulating Security Payload. Configure IKE-ESP ALG with NAT

  • TWAMP—Two-Way Active Measurement Protocol

Sample Output

ALG status

content_copy zoom_out_map
user@host> show security alg status
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Disabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

ALG status for a specific logical system

content_copy zoom_out_map
user@host> show security alg status logical-system LSYS1
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

ALG status for all logical systems including root logical system

content_copy zoom_out_map
user@host> show security alg status logical-system all
Logical system: root-logical-system
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

Logical system: LSYS3
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

Logical system: LSYS1
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

Logical system: LSYS2
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

Logical system: LSYS0
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Disabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

ALG status for a specific tenant system

content_copy zoom_out_map
user@host> show security alg status tenant TN1
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Enabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

ALG status for all tenant systems

content_copy zoom_out_map
user@host> show security alg status tenant all
Tenant : TN1
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Enabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

Tenant : TN2
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Enabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

ALG status for all logical systems and tenant systems

content_copy zoom_out_map
user@host> show security alg status all-logical-systems-tenants
Logical system : root-logical-system
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Disabled
  SCCP     : Disabled
  SIP      : Disabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

Logical system : LSYS1
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Enabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled
Tenant : TN1
ALG Status:
  DNS      : Enabled
  FTP      : Enabled
  H323     : Disabled
  MGCP     : Disabled
  MSRPC    : Enabled
  PPTP     : Enabled
  RSH      : Disabled
  RTSP     : Enabled
  SCCP     : Disabled
  SIP      : Enabled
  SQL      : Disabled
  SUNRPC   : Enabled
  TALK     : Enabled
  TFTP     : Enabled
  IKE-ESP  : Disabled
  TWAMP    : Disabled

Release Information

Command modified in Junos OS Release 9.5.

Command output is modified to display the details for the TWMAP ALG in Junos OS Release 18.2.

footer-navigation