Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Basic initial configuration steps for JuniperSRX (Security Policy 2)

Shulou Source: shulou.com Published: 2022-06-01 02:52:36 10月02日 Update

1) Interface

Set interfaces ge-0/0/0.0 family inet address x.x.x.x/24

Set interfaces ge-0/0/1.0 family inet address x.x.x.x/24

# show interfaces

# run show int terse

2) Security zone (add the interface to each security zone in)

Set security zones security-zone Outside/Inside or untrust/trust interface ge-0/0/0.0

# show security zones

3) Security policy-inter-zone policy (from inside to outside traffic-all permit; from outside to inside traffic-all deny)

Set security policies from-zone Inside to-zone Outside policy [Policy-Name] Default-Permit

Match source-address any

Match destination-address any

Match application any

Then permit

4) addressbook of the security zone (of each security zone)

/ / for match source-address\ destination-address any

Set security zones security-zone Outside address-book address [Address-Name] x.x.x.x/32

Set security zones security-zone Inside address-book address [Address-Name] x.x.x.x/32

5) configure application applications application or applications application-set

/ / for match application any

Set application [Application-Name] / / show applications

Set applications apolication [TCP-3032] protocol tcp destination-port 3032

Set applications application-set [APP-SET1] application TCP-3032

Show security flow session?

_

6) count

Edit security poicies from-zone Inside to-zone Outside policy Default-Permit

Set match source-address Inside-Network

Set match destination-address SP-Routers

Set match application any

Set then permit

Set then count

Set then log session-init session-close

Set system syslog file [Traffic-Log] any (facility) any (level severity level)

Set system syslog file [Traffice-log] match "RT_FLOW_SESSION"

> show security policies policy-name [Default-Permit] detail

> show system syslog

> show log [Traffice-Log]

7) monitor

# set system syslog file Monitor-Traffic-Log any any

# set system syslog file Monitor-Traffic-Log match "10.1.1.1"

# show system syslog

> monitor start Monitor-Traffic-Log

> monitor stop

8) debug of security flow traceoptions / / Juniper

9) Policy Schedulers / / time access control list

10) Web-Authen

11) Pass-Through

Tags: Security zone interface policy configuration time traffic level application control step Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Xiaomi MySQL Apple Redmi Shulou Technology