Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Announcement: Try the Ask AI chatbot for answers to your technical questions about Juniper products and solutions.

close
header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents

security-service (Security Forwarding Options)

date_range 09-Dec-23

Syntax

content_copy zoom_out_map
security-service (fail-open); 

Hierarchy Level

content_copy zoom_out_map
[edit security forwarding-options]

Description

The system resource management guarantees the resources are used according to priorities. the fail-open/fail-close impacts the new session creation only when the system resource is busy.

  • If system resource is not busy, fail-open/fail-close won't take effect. No impact to traffic.

  • If system resource is busy and the new session need not be created with Layer 7 services that require the system resource, then no impact to traffic.

  • . If system resource is busy, and the new session needs be created with Layer 7 services that require the system resource:

    • Fail-close (default), drops the packet and won't create the session

    • Fail-open, creates a flow session without the Layer 7 services that require the resource, and forward the packet out.

Options

  • fail-open—Ignores Layer 7 services with resource requirements, creates a flow session without Layer 7 services, and forward the packet out.

Required Privilege Level

security—To view this in the configuration.

security-control—To add this to the configuration.

Release Information

Support on SRX Series Firewalls for flow based security-service in Junos OS Release 20.4R1.

footer-navigation