This article provides a video and text instructions for configuring IDP on a SRX device. For other topics, go to the SRX Getting Started main page.
Go to the KBTV video or text instructions below:
root> request security idp security-package download check-server Successfully retrieved from(https://services.netscreen.com/cgi-bin/index.cgi). Version info:1577 (Detector=10.2.160091104, Templates=2)
root> request security idp security-package download
root> request security idp security-package download status
root> request security idp security-package download status In progress:downloading file ...platforms.xml.gz root> request security idp security-package download status Done; Successfully downloaded from(https://services.netscreen.com/cgi-bin/index.cgi). Version info:1586(Tue Jan 19 12:28:29 2010, Detector=10.2.160091104)
Important: When 'Successfully downloaded' is reported, proceed to the next step. If it is not successfully downloaded, the install will fail.
root> request security idp security-package install
This command loads the security package into the IDPD embedded DB. If there is an existing running policy it re-compiles the existing running policy and pushes the compiled policy to the data plane. Therefore, the install might take a while depending on the platform and the size of the policy. Lower end Branch platforms might take a longer time for install.
root> request security idp security-package install status
Done;Attack DB update : successful - [UpdateNumber=1581,ExportDate=Tue Jan 12 12:43:22 2010,Detector=10.2.160091104] Updating control-plane with new detector : successful Updating data-plane with new attack or detector : successful
root> show security idp security-package-version Attack database version:1577(Tue Jan 5 13:27:18 2010) Detector version :10.2.160091104 Policy template version :2
root> show security idp status
Session Statistics: [ICMP: 0] [TCP: 0] [UDP: 0] [Other: 0] Policy Name : Recommended v0 Running Detector Version : 10.2.160091104
root# set security policies from-zone trust to-zone untrust policy idp-app-policy-1 match source-address any destination-address any application any root# set security policies from-zone trust to-zone untrust policy idp-app-policy-1 then permit application-services idp Once this is configured and traffic is flowing through the SRX, IDP inspection should be occurring. To verify, enter the command root>show security idp status The command output should show that the counters are non zero, verifying that the IDP engine is seeing traffic. Tips: For additional information on enabling IDP in a Security Policy, refer to the Security Configuration Guide -- Enabling IDP in a Security Policy: http://www.juniper.net/techpubs/en_US/junos10.4/information-products/topic-collections/security/software-all/security/index.html?topic-42452.html
root# set security policies from-zone trust to-zone untrust policy idp-app-policy-1 match source-address any destination-address any application any root# set security policies from-zone trust to-zone untrust policy idp-app-policy-1 then permit application-services idp
root>show security idp status