View the demo

Setup guide

Juniper SRX: J-Flow and NAT from session logs

Export flows from a Juniper SRX firewall to Heimnull, and stream its session logs so every flow through NAT names the internal host behind it.

Updated 2026-10-11 · Tested on an SRX340 (Junos 23.4R2)

Tested only with Juniper SRX300-series branch firewalls, on an SRX340 running Junos 23.4R2. Other SRX models and Junos releases may name commands or log fields differently. Lines marked check on your release were written from Juniper’s documentation and not yet checked on a device: confirm them with ? completion before you commit.

This sets up two things:

  • Flows (J-Flow v9) on the internet (WAN) interface only. Each packet is counted once: inbound on input, outbound on output.
  • Session logs for every session that crosses NAT, so Heimnull knows which internal host is behind the public address in each WAN flow. This is the “NAT from session logs” switch on the exporter in Heimnull (Configure → Exporters).

Without session logs, WAN flows show only the public address, and sampling the LAN side as well counts traffic twice. Sampled LAN flows still wouldn’t tie the two sides together, because port translation changes the ports.

The examples use these addresses. Replace them with your own:

In the examples Value
Heimnull 10.0.0.10
SRX (LAN address, the flows’ source) 10.0.0.1
WAN interface ge-0/0/0.0
LAN 10.0.0.0/24 on irb.0
Public block 198.51.100.0/29

Flow export

Sample on the WAN unit only, on input and output, for IPv4 and IPv6:

set forwarding-options sampling instance NETFLOW input rate 100
set forwarding-options sampling instance NETFLOW family inet output flow-server 10.0.0.10 port 2055 version9 template NF-V4
set forwarding-options sampling instance NETFLOW family inet output inline-jflow source-address 10.0.0.1
set forwarding-options sampling instance NETFLOW family inet6 output flow-server 10.0.0.10 port 2055 version9 template NF-V6
set forwarding-options sampling instance NETFLOW family inet6 output inline-jflow source-address 10.0.0.1
set interfaces ge-0/0/0 unit 0 family inet sampling input
set interfaces ge-0/0/0 unit 0 family inet sampling output
set interfaces ge-0/0/0 unit 0 family inet6 sampling input
set interfaces ge-0/0/0 unit 0 family inet6 sampling output
  • Don’t add sampling to irb.0 or the other LAN units: that counts traffic twice.
  • In Heimnull, set the interfaces’ roles (Configure → Interface settings): ge-0/0/0.0 as Transit, and irb.0 and any other LAN units as Internal.
  • Add your public block to Networks.
  • Add the private LAN too if you want those hosts on host pages under their own hostgroup. NAT correlation works either way.

Session logs to Heimnull

Stream mode sends logs from the data plane, directly to Heimnull. The source address must be the one the flows come from, because Heimnull matches logs to the exporter by it.

set security log mode stream
set security log format sd-syslog
set security log source-address 10.0.0.1
set security log stream heimnull format sd-syslog
set security log stream heimnull category all
set security log stream heimnull host 10.0.0.10 port 5514
  • Check on your release: some releases take host 10.0.0.10 and host port 5514 as separate statements.
  • Port. 5514/udp is Heimnull’s default. Heimnull opens it only while at least one exporter has “NAT from session logs” on.
  • Category. all also sends screen and IDP messages; Heimnull ignores everything except session create and close, and counts the rest as ignored. Check whether your release offers a narrower session category.
  • Format. sd-syslog (RFC 5424 structured data) is the format Heimnull reads. syslog and binary aren’t supported.

Log the sessions that cross NAT

A session is logged only if its policy says so. Heimnull needs both the start (session-init) and the end (session-close):

  • The start gives the translation while the session is still running. With a 10-second flow timeout, flow records arrive long before a session closes.
  • The end lets Heimnull drop the translation soon after the session finishes.

List the policies that permit traffic:

show configuration security policies | display set | match "then permit"

Then, for each policy that permits traffic crossing NAT, add both logs:

set security policies from-zone trust to-zone untrust policy <name> then log session-init session-close
set security policies from-zone dmz to-zone untrust policy <name> then log session-init session-close
set security policies from-zone untrust to-zone trust policy <name> then log session-init session-close
  • Outbound policies (trust or dmz to untrust) cover traffic through source NAT.
  • Inbound policies (untrust to trust) cover your port forwards (destination NAT).
  • Not needed: policies between internal zones, or into GRE and IPsec tunnels, where there’s no NAT. Sessions without NAT are counted as “without NAT” and otherwise ignored.

Commit with commit check first, then commit confirmed 5, so a mistake rolls itself back.

Turn it on in Heimnull

Configure → Exporters → the SRX → NAT from session logs. The exporter page then shows:

  • how many messages arrived, and how many carried NAT;
  • when the last one arrived;
  • how many translations are held;
  • of the flows of NAT addresses, the share that matched a translation, outbound and inbound. Inbound flows without one are mostly unsolicited traffic (scans) that the firewall dropped, which opens no session. Flows of addresses without NAT (routed IPv6, public hosts) are counted apart and need none. ICMP and fragments match by addresses.

Check it

On the SRX:

show security flow session nat                     # live translations
show security log stream statistics                # check on your release

On the Heimnull host, a few messages should arrive within seconds of browsing from the LAN:

sudo tcpdump -n -A -c 5 udp port 5514

In Heimnull:

  • A host behind NAT appears in flow records as public → internal.
  • Its host page (open the internal address) lists its traffic.
  • Threat-feed contacts name the internal host.

Notes and limits

  • Volume. Two messages per session. A busy office of a few hundred hosts sends tens of messages a second, far below what the listener handles. Heimnull keeps each translation until 3 minutes after its session closes, for late flow records, and at most 24 hours if the close is lost.
  • UDP loss. A lost start leaves that session’s flows without the internal host until its close arrives. A lost close makes the translation last up to 24 hours, which is harmless.
  • IPv6 is usually routed, not translated: its flows already show the internal host and need no logs.
  • Tunnels. Traffic inside GRE and IPsec tunnels isn’t sampled on the WAN unit (only the outer packets are), so it isn’t in the flows either.
  • Security. Logs are accepted only from the address of an approved exporter with the switch on. Anything else is counted as “unknown source” and dropped.

Questions about your setup?

Write to us with your router model and software release, or try the demo to see what Heimnull does with the data.

info@heimnull.com