unidirectional-session-refreshing
Syntax
unidirectional-session-refreshing;
Hierarchy Level
[edit security zones security-zone]
Description
Use unidirectional session refreshing on a zone to enable two options for a session. Refresh a session by any packet from any directions. This is a default behavior. Refresh a session by only the packets in the initial direction.
USR (Unidirectional Session Refresh) is skipped for PPTP and IKE ALG data sessions in cases where USR is enabled on only one security zone, but data traffic originates from the opposite zone. For instance, if USR is enabled on the "Trust" zone but disabled on the "Untrust" zone, then for a PPTP ALG data session originating from the "Untrust" zone (where traffic flows unidirectionally from public to private), USR will be skipped.
Required Privilege Level
security
Release Information
Statement introduced in Junos OS Release 20.4R1.