- In Security Director, navigate to Devices and select Click here to Discover Devices.
- Follow the prompts to add a device target. In this example, we will add the SRX via its IP address.
- Continue to follow the prompts to add options like ping, SNMP, and SSH as methods to discover the device.
- Select Discover. Upon completion a status page will be displayed showing success.
- Navigate to Security Director Devices to verify configuration/connection status, and the schema version in use.
- If the schema version is out of date:
- Navigate to Network Management Platform -> Administration -> DMI Schemas -> Update Schema
- Select SVN Repository and then Configure
- Enter https://xml.juniper.net/dmi/repository/trunk/ for SVN URL
- Enter your Juniper Networks support credentials
- Test the connection and then save
- For Device Family select junos-es
- Click Connect
- Select the Junos version that matches the version installed on the SRX and click Install
- Once installed, navigate back to Network Management Platform -> Administration -> DMI Schemas, select the OS version recently installed and then under actions select Set as Default Scheme
- Navigate back to Security Director -> Security Director Devices to verify that the correct schema version is showing
- Right-click the device and select Import
- Select the policies to import (in this case we would import both NAT and Firewall policies, and click Next
- A summary will be shown listing the configuration elements to be imported. Click Finish.
- A summary will be shown listing the configuration elements that were imported. Click Close.
- Navigate to NAT Policies, right-click on the SRX host name and select Assign Devices
- Select the SRX host name and then select Modify
- In NAT Policies, right-click the on the SRX host name and select Publish NAT Policy
- Click Publish and then verify that it was successful
- Navigate to Firewall Policies, right-click on the SRX host name and select Assign Devices
- Select the SRX host name and then select Modify
- In Firewall Policies, right-click the on the SRX host name and select Publish Policy
- Click Publish and then verify that it was successful
- To test things out, navigate to Firewall Policies, click on the SRX, and then click on the green lock to edit.
- Modify or create a policy (in my case, I changed an existing policy's action from permit to deny)
- Click Save and the right-click the SRX and select Publish
- Click on Publish and Update
- Verify that the update was successful by viewing the job status and/or doing a show | compare from operational mode in the CLI
- Don't forget to revert your change after testing is complete :)
A collection of tutorials, designed to assist systems engineers in the integration of different technical solutions.
Tuesday, September 22, 2015
Junos Space Security Director - Part III
The third part of this guide demonstrates how to import an SRX series firewall into Junos Space (version 14.1R3.4). It assumes that Junos Space, Security Director, and a Log Collector are already deployed and operational. For steps on how to install Junos Space components, start here.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment