When a new packet arrives that does not match an existing session, the SRX performs full flow-based processing. After ingress zone determination, the firewall must know the destination zone to evaluate security policies.
The SRX determines the egress zone by performing a route lookup on the packet’s destination IP address.
The routing decision identifies the outgoing interface, and the zone associated with that interface becomes the egress zone .
Session lookup (Option A) happens first but is only useful for existing sessions.
Destination port (Option B) is used for application identification, not zone determination.
Ingress zone properties (Option D) cannot determine the egress zone.
[Reference: Juniper Networks – SRX Series Flow Processing and Security Zone Determination, Junos OS Security Fundamentals., ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit