Disconnect connection in use on Juniper Netscreen 25 firewall

Posted on 2009-04-21
Last Modified: 2013-11-16
From the GUI:
Objects > Addresses > List
I have a couple of IP addresses that are showing "In Use" that i want to disconnect and then block (including logging for attempts). I am fairly certain i am configuring the block rule correctly, however, this connection has been in a status of "In Use" for quite some time now.

I configured the block rule under:
Policies > Untrust to Trust ANY ANY Deny (Logging enabled)

I want to disconnect any active connections, and ensure this IP address is not connected. Thanks for your help!
Question by:mray77
    LVL 18

    Accepted Solution

    The list you mention does not tell you if the object is connected bud.

    Objects > Addresses > List is just a list.

    The part re "in use" means that this object is "in use" in a security rule.  Unless you delete all rules and references to the object, it will always say "in use".

    To see if there are any live connections going through the box regarding a specific host then you will be better using the CLI.

    Use the following:

    get session src-ip <ip address of host>
    get session dst-ip <ip address of host>

    Have a look at the output, if you want to block all sessions, then your end result is to have nothing returned to both of these.  If there are any entries returned, review the src and dst in the entries and add more rules.

    Author Comment

    Awesome. Thanks. Obviously i'm pretty green with the GUI.
    LVL 18

    Expert Comment

    No worries bud, we all start somewhere.

    Let us know if you need anything else. :P

    Featured Post

    Do You Know the 4 Main Threat Actor Types?

    Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

    Join & Write a Comment

    Suggested Solutions

    We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
    Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now