Juniper IDP Test License Application, database installation, call; Log server calls IDP Log

Source: Internet
Author: User
Tags syslog

License Application:
[Email protected]> Request System License Update trial

Update feature library requires configuration of DNS configuration, correct time configuration, downloaded URL
Security {
IDP {
Security-package {
URL https://services.netscreen.com/cgi-bin/index.cgi;
}
}

You need to update the feature library before you complete the global configuration
1. Download Feature Library
[Email protected]> request Security IDP Security-package download
2. Update
[Email protected]> Request Security IDP Security-package Install

IPs configuration Method:

IDP-Corresponding rule: (global)
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match from-zone any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match source-address any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match to-zone any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match destination-address any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match application Default
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Critical-ip"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Critical-tcp"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Major-tcp"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Major-ip"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 then action No-action
Set security IDP Idp-policy idp_default rulebase-ips rule 1 then notification Log-attacks alert
Set Security IDP Active-policy Idp_default

Called in a specific policy, for example:
Set security Policies From-zone Trust To-zone untrust policy t-u-1 match source-address any
Set security Policies From-zone Trust To-zone untrust policy t-u-1 match destination-address any
Set security Policies From-zone Trust To-zone untrust policy t-u-1 then permit application-services IDP

Log view:
If you view the IDP log directly in your device, you need to do two steps:
1.
Security {
Log {
Mode event;
Event-rate 1500;
}
}
Log forwarded from Data-plane to Control-plane

2. Add idp_log file to record IDP information
Set system Syslog file Idp_log any any
Set system Syslog file Idp_log match RT_IDP
Set System Syslog file Idp_log Archive size 10m
Set System syslog file Idp_log archive files 10

Juniper IDP Test License Application, database installation, call; Log server calls IDP Log

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.