Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

global (Security Policies)

date_range 20-Nov-23

Syntax

content_copy zoom_out_map
global {
    policy policy-name {
        description description;
        match {
            application {
                [application];
                any;
            }
            destination-address {
                [address];
                any;
                any-ipv4;
                any-ipv6;
            }
            from-zone {
                [zone-name];
                any;
            }
            source-address {
                [address];
                any;
                any-ipv4;
                any-ipv6;
            }
            source-identity {
                [role-name];
                any;
                authenticated-user;
                unauthenticated-user;
                unknown-user;
            }
                to-zone {
                    [zone-name];
                    any;
                }
        }
        scheduler-name scheduler-name;
        then {
                                 count { 
                alarm {
                    per-minute-threshold number; 
                    per-second-threshold number;
                }
            }
            deny;
            log {
                session-close;
                session-init;
            }
            permit {
                application-services {
                    application-firewall {
                        rule-set rule-set-name;
                    }
                    application-traffic-control {
                        rule-set rule-set-name;
                    }
                    gprs-gtp-profile profile-name;
                    gprs-sctp-profile profile-name;
                    idp;
                    redirect-wx | reverse-redirect-wx;
                    ssl-proxy {
                        profile-name profile-name;
                    }
                    uac-policy {
                        captive-portal captive-portal;
                    }
                    utm-policy policy-name;
                }
                destination-address {
                    drop-translated;
                    drop-untranslated;
                }
                firewall-authentication {
                    pass-through {
                        access-profile profile-name;
                        client-match user-or-group-name;
                        web-redirect;
                    }
                    web-authentication {
                        client-match user-or-group-name;
                    }
                }
                services-offload;
                tcp-options {
                    sequence-check-required;
                    syn-check-required;
                }
            }
            reject;
        }
    }
}

Hierarchy Level

content_copy zoom_out_map
[edit security policies]

Description

Configure a global policy.

Options

The remaining statements are explained separately. See CLI Explorer.

Required Privilege Level

security—To view this statement in the configuration.

security-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 8.5. Statement updated with from-zone and to-zone policy match options in Junos OS Release 12.1X47-D10.

footer-navigation