Security & Firewalls
Sep 25, 2026
3 min read
An IDP policy attached to a security policy does not mean traffic is inspected. The community thread 'Either configure idp or idp-policy and not both' shows the confusion — here is how IDP actually engages and how to verify inspection is happening.
Security & Firewalls
Sep 24, 2026
3 min read
'Everything works until we enable screens, then traffic dies' is a classic SRX support thread. Flood and scan screens have real thresholds and real side effects — here is how to read the counters and tune the values instead of disabling protection.
Security & Firewalls
Sep 24, 2026
4 min read
The tunnel was fine yesterday. Today it is down. Follow the Juniper KB approach: determine whether Phase 1 or Phase 2 failed, match proposals, proxy-IDs and PSKs, and use IKE traceoptions when nothing else explains it.
Security & Firewalls
Sep 23, 2026
10 min read
FortiGate suits most small offices without Junos skills, SRX suits Junos shops and routing-heavy branches, and Palo Alto suits security-first buyers. This comparison uses published datasheet numbers, explains which throughput row actually matters, and shows how to trial an SRX properly.
Security & Firewalls
Sep 23, 2026
10 min read
SASE is SD-WAN plus cloud-delivered security (SSE), enforced at vendor PoPs instead of your headquarters firewall. This guide explains the architecture, maps the 2026 vendor field including HPE and Juniper, and shows how to tunnel an SRX branch into an SSE PoP with fail-open or fail-closed routing.
Security & Firewalls
Sep 23, 2026
11 min read
Build an SRX site to site VPN as a route-based IKEv2 tunnel on st0, with a copy-ready Junos config, healthy and broken show output, and an ordered diagnostic. Includes the FortiGate and Palo Alto interop gotchas and the PFS mismatch that kills new tunnels at the first rekey.