# set security flow tcp-session no-syn-check
- 關閉 TCP Sequence check
# set security flow tcp-session no-sequence-check
- 關閉 DNS Reply check
* SRX 預設會對 DNS 封包(UDP dst-port 53)進行過濾,如果去回不同路所造成 SRX 看不到 quary 封包(Quary Bit = 0),這時侯當 SRX 收到 Response 封包時(Quary Bit = 1),即會將此封包 drop。
* # set security flow allow-dns-reply