Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

Firewall terms might not be evaluated sequentially



Article ID: JSA10313 SECURITY_ADVISORIES Last Updated: 09 May 2013Version: 2.0
Legacy Advisory Id:
Product Affected:
All M-series and T-series routers with firewall filters that contain both from source-address and from address match conditions.
When a firewall filter term includes the from address
match condition and a subsequent term includes the from source-address
match condition for the same address, packets might be processed by the latter term before they are evaluated by any intervening terms. Therefore, packets that should be rejected by the intervening terms may be accepted, or packets that should be accepted may be rejected.

This behavior occurs because of an optimization within the firewall compiler. It is being tracked by PR/28108
There is no solution at this time. Juniper Networks is continuing to investigate this problem.
As a workaround, for every firewall filter term that contains the from address
match condition, replace that term with two separate terms, one that contains the from source-address
match condition and one that contains the from destination-address
match condition.
Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search