通过show log nsd_chk_only | no-more 可查看Juniper SRX系列防火墙的系统相关限制。
比如说Policy策略最大数、策略调用Address地址簿最大数、策略调用Applications应用最大数、NAT最大数、Zone区域最大数等相关信息。
以下为Juniper SRX5600输出结果
SRX5600> show log nsd_chk_only | no-more
Matching platform :
Model Name = srx5600
Hardware Model = srx5600
Description = australia
Policy Capacity Config :
Max Policy = 80000
Max Policy Context = 8192
Max Policy per Context = 10240
Max Statistics Counter = 1024
Max Address per Policy = 1024
Max Applications per Policy = 128
Scheduler Capacity Config :
Max Scheduler = 64
Zones Capacity Config :
Max Security Zones = 2000
NAT rule Capacity Config :
Source NAT rule number = 8192
Dest NAT rule number = 8192
Static NAT rule number = 8192
Ds-lite SC number = 32
Source NAT rule-set number = 8192
Dest NAT rule-set number = 8192
Static NAT rule-set number = 8192
原文地址:http://blog.51cto.com/3990129/2083553