Juniper SRX 安全区域与安全策略配置实战教程 - 夜莺博客

Juniper SRX 安全区域与安全策略配置实战教程

很多工程师第一次接手 SRX 时会把注意力全放在 NAT 和路由上,结果配完发现 ping 不通、SSH 也进不去。根因几乎都不是路由问题,而是漏掉了 SRX 的区域模型:接口必须先绑定到安全区域(security-zone),策略必须写在「源区域 → 目的区域」的上下文里,管理流量还必须单独用 host-inbound-traffic 放行。本文按真实上线顺序,把区域、地址簿、应用与策略四步串起来,每一段都给出可直接粘贴的 set 命令和验证命令,最后给出策略不命中的排查路径。适合刚接手 SRX300/SRX1500/SRX4100 系列设备的运维工程师按图施工。

为什么 SRX 必须先配区域再配策略

SRX 是 zone-based 状态防火墙。数据包进入设备后,先按入接口所属区域确定 from-zone,再按出接口确定 to-zone,然后用该 zone pair 下的策略做匹配。没有绑定区域的接口,其流量既没有 from-zone 也没有 to-zone,任何策略都无法命中,表现就是「路由没问题但业务不通」。

策略匹配是从上到下、首条命中即生效。Junos 允许策略引用地址簿(address-book)和应用(application)对象,因此工程上推荐先把地址和应用命名化,再写策略,后期维护时改地址簿即可,不必动策略本身。区域、接口与策略的关系,和 Cisco 上 zone-based firewall 的 zone-pair 思路一致,可以对照 站内 Cisco IOS Zone-Based Firewall 配置 一起理解。

前置条件与规划

# 本文示例拓扑
ge-0/0/0  10.10.1.1/24  -> trust 区域(内网)
ge-0/0/1  203.0.113.2/30 -> untrust 区域(公网)
# 目标:内网可出公网 HTTP/HTTPS/DNS,公网只能 SSH 到设备,其余默认拒绝

第一步:创建安全区域并绑定接口

区域名可自定义,但 inbound 与 outbound 的方向由接口决定。SRX 上每个接口只能属于一个区域。

set security zones security-zone trust host-inbound-traffic system-services ping
set security zones security-zone trust host-inbound-traffic protocols ospf
set security zones security-zone trust interfaces ge-0/0/0.0

set security zones security-zone untrust host-inbound-traffic system-services ssh
set security zones security-zone untrust host-inbound-traffic system-services ping
set security zones security-zone untrust interfaces ge-0/0/1.0

host-inbound-traffic 为什么必须单独配

它控制的是送到设备自身的流量(管理、路由协议、ICMP)。即使你写了一条 trust→untrust 的 permit any 策略,SSH 到 untrust 接口依然会被丢包,因为策略只作用于 transit 流量。这是 SRX 上线阶段最常见的「能上网但进不来设备」的原因。

第二步:配置地址簿与地址集

set security address-book global address web-server-1 10.10.1.20/32
set security address-book global address-sets internal-servers 10.10.1.0/24
set security address-book global address-sets public-dns 8.8.8.8/32
set security address-book global address-sets public-dns 1.1.1.1/32

地址集(address-set)可以嵌套,方便把业务网段整体授权。地址与地址集在同一命名空间内,名字不能重复,commit 时会做重名检查。

第三步:定义应用对象

set applications application app-web protocol tcp destination-port 80
set applications application app-web protocol tcp destination-port 443
set applications application app-dns protocol udp destination-port 53
set applications application-set app-internet application app-web
set applications application-set app-internet application app-dns

第四步:编写安全策略

set security policies from-zone trust to-zone untrust policy allow-internet match source-address internal-servers
set security policies from-zone trust to-zone untrust policy allow-internet match destination-address any
set security policies from-zone trust to-zone untrust policy allow-internet match application app-internet
set security policies from-zone trust to-zone untrust policy allow-internet then permit
set security policies from-zone trust to-zone untrust policy allow-internet then log session-init
set security policies from-zone trust to-zone untrust policy allow-internet then log session-close

set security policies from-zone untrust to-zone trust policy deny-all match source-address any
set security policies from-zone untrust to-zone trust policy deny-all match destination-address any
set security policies from-zone untrust to-zone trust policy deny-all match application any
set security policies from-zone untrust to-zone trust policy deny-all then deny

显式写一条 match any / then deny 是业界推荐做法:默认 deny 虽然存在,但显式策略会在 hit-count 里留下计数,排查时一眼看出「确实被策略拦了」而不是被 screen 或路由丢掉。

安全提交:commit confirmed 与回滚

commit confirmed 5      # 5 分钟后自动回滚,除非再次 commit
commit                  # 确认本次配置
rollback 1              # 如需回退到上一版本

远程改防火墙一定要用 commit confirmed,否则一条错误的 host-inbound 配置就能把自己关在门外。该机制的完整用法见 Junos commit confirmed 与安全回滚。

验证:四条命令确认策略真的生效

show security zones                 # 区域、接口、host-inbound 服务
show security policies              # 策略顺序与 enable 状态
show security policies hit-count    # 每条策略命中次数(判断是否被匹配)
show security flow session summary  # 会话数量与状态
show security flow session source-prefix 10.10.1.20

排障顺序建议:先看 hit-count 是否有增长。若 allow-internet 计数不动、deny-all 计数在涨,说明匹配到了错误策略或地址对象写错;若两者都不动,说明包根本没到策略引擎,问题在路由、区域绑定或 screen 上。

常见故障对照表

现象                          最可能原因
能上网但 SSH 不进设备          host-inbound-traffic 未放行 system-services ssh
策略不命中、计数为 0           接口未绑定区域 / 包未做路由查询
部分业务不通                   application 的 destination-port 写错
NAT 后源地址变化导致不命中     策略源地址应写内网真实地址而非 NAT 后地址
策略顺序错了                  any/any permit 放在具体策略之前

NAT 与策略的先后关系经常被误解,建议对照 Junos SRX 源 NAT 与目的 NAT 配置 一起看;如果两台 SRX 做了 chassis cluster,还要确认策略与区域是否同步到了备机,参考 SRX 双机热备配置指南。

FAQ

Q:区域必须至少两个吗? 是。单区域下没有 zone pair,策略无处可写;SRX 至少要划分 trust 与 untrust 两个区域。
Q:能不能用 any 应用? 可以,但审计和排障会变得困难,生产环境建议用 application-set 收敛端口。
Q:策略改了要重启吗? 不需要,commit 后立即生效,已建立的会话不受影响,可用 clear security flow session all 强制重建。

原文链接:https://www.juniper.net/documentation/us/en/software/junos/security-policies/topics/topic-map/security-zone-configuration.html