NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6317
http://www.securityfocus.com/bid/2523
http://archives.neohapsis.com/archives/bugtraq/2001-03/0375.html