This guide helps you verify/troubleshoot whether the IDP attack database is downloaded and installed on an SRX device.
Perform the following steps:
Run the command 'show security idp security-package-version'.
user@srx> show security idp security-package-version node0: ---------------------------------------------------------------- Attack database version :3410(Tue Aug 17 18:02:08 2021 UTC) <------ Detector version : 12.6.130200828 Policy template version :N/A
user@srx> show security idp security-package-version node0: ----------------------------------------------------------------
Attack database version
:3410(Tue Aug 17 18:02:08 2021 UTC) <------ Detector version : 12.6.130200828
Policy template version :N/A
Does the 'Attack database version' have a recent date?
:N/A(N/A)
<------ Detector version :12.6.140121210
delete system processes idp-policy disable
Run the command ' show system license '.
show system license
Do you see the feature ' idp-sig ' (which is the IDP license)?
Then jump to Step 4 to check the status.
Consider setting up the IDP signature database to be updated automatically. For more information, refer to KB16491 - How to update IDP signature database automatically [juniper.net] .
Then continue to Step 4 to check the status.
Check the status of the Attack database download with the following command. (You may have to repeatedly run the command if it is 'in Progress'.)
user@srx> request security idp security-package download status
What is the status?
Check the status of the Attack database install with the following command. (You may have to repeatedly run the command if it is 'in Progress'.)
user@srx> request security idp security-package install status
2021-09-11: Updated the command output with the latest version of IDP and removed cluster related IDP configuration as it's only valid for EOL/EOE version, i.e below 12.1