穿越Ping流量,从Router-A-10.10.10.1-----------VSRX--------------20.20.20.1-Router-B
- 当Router-B没有回程路由时,此时从A到Ping到B,分析防火墙上的ICMP会话, 当对端无回包时,ICMP的Timeout是60秒。
root@vSRX> show security flow session protocol icmp |refresh 1 |no-more
Jul 25 07:03:10
—(refreshed at 2020-07-25 07:03:10 UTC)—
Total sessions: 0
Jul 25 07:03:11
—(refreshed at 2020-07-25 07:03:11 UTC)—
Total sessions: 0
Jul 25 07:03:12
—(refreshed at 2020-07-25 07:03:12 UTC)—
Session ID: 47, Policy name: 1/4, Timeout: 60, Valid
In: 10.10.10.1/0 --> 20.20.20.1/19478;icmp, If: ge-0/0/2.0, Pkts: 1, Bytes: 84
Out: 20.20.20.1/19478 --> 10.10.10.1/0;icmp, If: ge-0/0/3.0, Pkts: 0, Bytes: 0
Total sessions: 1
Jul 25 07:03:13
—(refreshed at 2020-07-25 07:03:13 UTC)—
Session ID