License Application:
[Email protected]> Request System License Update trial
Update feature library requires configuration of DNS configuration, correct time configuration, downloaded URL
Security {
IDP {
Security-package {
URL https://services.netscreen.com/cgi-bin/index.cgi;
}
}
You need to update the feature library before you complete the global configuration
1. Download Feature Library
[Email protected]> request Security IDP Security-package download
2. Update
[Email protected]> Request Security IDP Security-package Install
IPs configuration Method:
IDP-Corresponding rule: (global)
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match from-zone any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match source-address any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match to-zone any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match destination-address any
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match application Default
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Critical-ip"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Critical-tcp"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Major-tcp"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 match attacks predefined-attack-groups "Major-ip"
Set security IDP Idp-policy idp_default rulebase-ips Rule 1 then action No-action
Set security IDP Idp-policy idp_default rulebase-ips rule 1 then notification Log-attacks alert
Set Security IDP Active-policy Idp_default
Called in a specific policy, for example:
Set security Policies From-zone Trust To-zone untrust policy t-u-1 match source-address any
Set security Policies From-zone Trust To-zone untrust policy t-u-1 match destination-address any
Set security Policies From-zone Trust To-zone untrust policy t-u-1 then permit application-services IDP
Log view:
If you view the IDP log directly in your device, you need to do two steps:
1.
Security {
Log {
Mode event;
Event-rate 1500;
}
}
Log forwarded from Data-plane to Control-plane
2. Add idp_log file to record IDP information
Set system Syslog file Idp_log any any
Set system Syslog file Idp_log match RT_IDP
Set System Syslog file Idp_log Archive size 10m
Set System syslog file Idp_log archive files 10
Juniper IDP Test License Application, database installation, call; Log server calls IDP Log