Dynamic routing on firewalls.

ML ml at kenweb.org
Thu Feb 5 14:53:24 UTC 2015


On 2/5/2015 9:42 AM, Eugeniu Patrascu wrote:
> On Juniper things tend work OK. Other than this, make sure you don't 
> run into asymmetric routing as connections might get dropped because 
> the firewall does not know about them or packets arrive out of order 
> and the firewall cannot reassemble all of them. 

Agreed.  Assymmetric routing is not your friend unless you plan 
accordingly.

I use OSPF and BGP quite a bit on Juniper SRX.  Works great.



More information about the NANOG mailing list