some things about policies/sessions

1)  An ICMP packet occupies a session entry in SRX

2) There is an intra-zone policy applied by default so packets belonging to the same zone but in different interfaces cannot traverse unless there is a intra-zone policy permitting them.

3) If the policy doesn’t allow a packet, it cannot be seen in monitor traffic command.

