This article provides information on how to activate the SSH tunnels between managed hosts and the console.
To encrypt the data flow between JSA/STRM managed hosts (EC/EP and FC/FP) and the console, encryption must be enabled when adding managed hosts in the deployment editor.
The SSH tunnels are activated when adding a managed host. When you enter the address of the new system during the add process, the following checkboxes are present at the bottom:
Enable encryption
When you enable encryption, the communication from the host, which is marked as encrypted, is sent through the SSH tunnels on port 22. If you want to have both directions encrypted, you will also need to enable this for the QRadar console.
Right click each IP address that you want to encrypt, select Edit Managed Host and click the Next button.
For more information, refer to the Juniper Secure Analytics (formally known as STRM) Administration Guide (for Release 2014.7, the information can found in Chapter 10: Deployment Editor). To download and view the admin guide for your installed version of STRM, refer to the following link:
2017-03-24: Added references to JSA and linked to technical documentation.