Got it

Why the security policy name is displayed as --- in the session table?

Created: Jun 5, 2019 07:26:06Latest reply: Jun 5, 2019 07:50:31 467 1 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

I look the session table information by the command display firewall session table, but the security policy name is displayed ---, why?

Featured Answers
dr.wow
Official Created Jun 5, 2019 07:50:31

Hey there!

In the following scenarios, the policy name field in the session table is displayed as ---:

1. If an application-based security policy is configured and the application is not identified, the packet is sent to the IAE for application identification. In this case, the policy name in the session table is displayed as ---. The policy can be matched and displayed only after the application is identified.

2. Traffic in the same security zone is permitted by default.

3. The service-manage function is enabled on the interface, and security policy matching is not performed.

4. If packets match the authentication policy, portal authentication instead of security policy matching is performed.

5. When the endpoint-independent filter is enabled, security policy matching is not performed.

6. The standby device backs up sessions from the active device, and no packets pass through the standby device.

7. Services in other forwarding processes do not match security policies.

For other information, please refer to the product documentation:
View more
  • x
  • convention:

All Answers
dr.wow
dr.wow Official Created Jun 5, 2019 07:50:31

Hey there!

In the following scenarios, the policy name field in the session table is displayed as ---:

1. If an application-based security policy is configured and the application is not identified, the packet is sent to the IAE for application identification. In this case, the policy name in the session table is displayed as ---. The policy can be matched and displayed only after the application is identified.

2. Traffic in the same security zone is permitted by default.

3. The service-manage function is enabled on the interface, and security policy matching is not performed.

4. If packets match the authentication policy, portal authentication instead of security policy matching is performed.

5. When the endpoint-independent filter is enabled, security policy matching is not performed.

6. The standby device backs up sessions from the active device, and no packets pass through the standby device.

7. Services in other forwarding processes do not match security policies.

For other information, please refer to the product documentation:
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.