Which configuration must be completed to use both packet-based and session-based forwarding on a branch
SRX Series Services Gateway?
A.
A stateless firewall filter must be used on the ingress interface to match traffic to be processed as session
based.
B.
A security policy rule must be used on the ingress interface to match traffic to be processed as session
based.
C.
A global security policy rule must be used on the ingress interface to match traffic to be processed as packet
based.
D.
A stateless firewall filter must be used on the ingress interface to match traffic to be processed as packet
based.
D
Branch SRX devices can use both packet-based and session-based forwarding simultaneously. This functionality is called Junos Selective Stateless Packet-Based Services. A stateless firewall filter on the inbound interface can specify any matching traffic to be processed as packet-based, in which case the traffic will bypass the services and security features within the flow module. Otherwise, the rest of the traffic will be processed within the flow module as session-based traffic.