Table 12: show security flow session Output Fields (continued)
Field DescriptionField Name
Reverse flow (source and destination IP addresses, application protocol, interface,
session token, route, gateway, tunnel, port sequence, FIN sequence, FIN state, packets
and bytes).
Out
Total number of sessions.Total sessions
Session status.Status
Internal flag depicting the state of the session, used for debugging purposes. The three
available flags are:
• flag
• natflag
• natflag2
Flag
Name and ID of the policy that the first packet of the session matched.Policy name
The name of the source pool where NAT is used.Source NAT pool
Name of the application.Dynamic application
AppQoS rule set for this session.Application traffic control rule-set
AppQoS rule for this session.Rule
The AppQoS forwarding class name for this session that distinguishes the transmission
priority
Forwarding class
Differentiated Services (DiffServ) code point (DSCP) value remarked by the matching
rule for this session.
DSCP code point
One of four priority levels set by the matching rule to control discarding a packet during
periods of congestion. A high loss priority means a high probability that the packet could
be dropped during a period of congestion.
Loss priority
The rate-limiter profile assigned to the client-to-server traffic defining a unique
combination of bandwidth-limit and burst-size-limit specifications.
Rate limiter client to server
The rate-limiter profile assigned to the server-to-client traffic defining a unique
combination of bandwidth-limit and burst-size-limit specifications.
Rate limiter server to client
Maximum session timeout.Maximum timeout
Remaining time for the session unless traffic exists in the session.Current timeout
Session state.Session State
Time when the session was created, offset from the system start time.Start time
111Copyright © 2016, Juniper Networks, Inc.
Chapter 12: Operational Commands