Cloud Feeds configuration:
Pre-requisites:
2. Allow the Policy Enforcer to reach out to the following servers for completing the enrollment, registration into SKY ATP. Select the right list based on the region.
North America Region
European Region
Asia Pacific Region
3. Check the software on the SRX device to confirm if that matches the version that supports Security Intelligence.
- show version - show configuration services security-intelligence
https://www.juniper.net/techpubs/en_US/release-independent/policy-enforcer/topics/task/installation/policy-enforcer-vm-config.html
https://www.juniper.net/techpubs/en_US/release-independent/policy-enforcer/topics/concept/junos-space-policy-enforcer-cloud-feeds-setup-overview.html
5. Login to Security Director.
a) Configure PE using Administration -> PE Settings.
NOTE: Please ensure you select the right “Threat Prevention Type”. If you select “Could Feeds Only” you can select other “Threat Prevention Types” but if you select “SKY ATP with PE” you cannot go back to “Cloud Feeds only”. In that case, you will need to rebuild the policy enforcer.
b) Successful message is received once the PE is configured.
Note: You can use Guided setup which will help you with every steps or you can with each steps one by one by selecting cancel button
c) Select Configure -> Threat Prevention -> Feed Source -> Sky ATP Realms
d) Once the Sky ATP realm is added, click on the “Add Devices” link to add the devices that would need the cloud feeds to be configured.
e) Once devices are added, add a Threat prevention policy to configure the “Command and Control” feeds.
f) Once the Threat prevention policy is configured, the connector is setup. Now use this Threat prevention policy in a firewall policy.
g) Publish and Update the firewall policy to the device.
h) Make sure Cloud feed is enabled over SKY ATP portal and reflected under shared -> address objects page over SD UI. 1) Login to SKY ATP portal and enable required cloud DAG feed for example: office365, Zscaler etc
i) Include the required DAG objects to firewall rules as per requirement and perform publish/update on the managed SRX device. j) After successful update operation, device should show the cloud DAG feed
Device Validation:
Once the device and PE is configured, please check the following values to confirm if the connectivity is fine on the SRX and PESRX => PE 443, Internet 80,8080,443Please find below URL for PE ports details https://www.juniper.net/documentation/us/en/software/nm-apps23.1/policy-enforcer-user-guide/topics/concept/policy-enforcer-ports.html
Note: If we are using SDI as Policy enforcer then port might be different then legacy PE, please refer SDI-PE user guide for the same.
[email protected]> show version Hostname: vSRX-23.4R1.9 Model: vSRX Junos: 23.4R1.9
SecIntel Check: The configuration below shows the association to Policy Enforcer.
[email protected]> show configuration services security-intelligence | display set | no-more set services security-intelligence url https://10.219.87.34:443/api/v1/manifest.xml set services security-intelligence authentication auth-token KZUX03ZI6AJ577C9UUPXM423A1QXYBS4 Check if feeds are downloaded using the following commands: [email protected]> show services security-intelligence update status Current action :Checking update interval of category GeoIP. Last update status :Update interval of category CC is not reached. Last connection status:succeeded Last update time :2024-02-19 09:57:16 UTC [email protected]> request services security-intelligence download status Security intelligence feed download status: Start time:Mon Feb 19 06:13:06 2024 Start downloading the latest manifest. Start parsing manifest file. Parse manifest succeeded, version:f247934317b59e2cf9e82e942d21497c. End time:Mon Feb 19 06:13:06 2024 [email protected]> show security dynamic-address address-name ? Possible completions: <address-name> Dynamic address name JTAC-GeoIP ipfilter_cloudflare ipfilter_facebook ipfilter_office365 ipfilter_paypal ipfilter_sdcloud ipfilter_zscaler [email protected]> show security dynamic-address address-name ipfilter_office365 No. IP-start IP-end Feed Address 1 13.107.6.152 13.107.6.153 IPFilter/ipfilter_office365 ipfilter_office365 2 13.107.6.171 13.107.6.171 IPFilter/ipfilter_office365 ipfilter_office365 3 13.107.6.192 13.107.6.192 IPFilter/ipfilter_office365 ipfilter_office365 4 13.107.9.192 13.107.9.192 IPFilter/ipfilter_office365 ipfilter_office365 5 13.107.18.10 13.107.18.11 IPFilter/ipfilter_office365 ipfilter_office365 6 13.107.18.15 13.107.18.15 IPFilter/ipfilter_office365 ipfilter_office365 7 13.107.64.0 13.107.127.255 IPFilter/ipfilter_office365 ipfilter_office365 [email protected]> show security dynamic-address category-name CC No. IP-start IP-end Feed Address CountryCode 1 1.0.4.1 1.0.4.1 CC/3 ID-fffc0831 -- 2 1.0.5.1 1.0.5.1 CC/3 ID-fffc0831 -- 3 1.0.6.1 1.0.6.1 CC/3 ID-fffc0831 -- 4 1.0.7.1 1.0.7.1 CC/3 ID-fffc0831 -- 5 1.0.16.1 1.0.16.1 CC/3 ID-fffc0831 -- 6 1.0.32.1 1.0.32.1 CC/3 ID-fffc0831 -- The end octet of the address entry “ID-fffc0831” would indicate the threat level of the address.
Run the command below to list all the feed categories downloaded to the SRX device:
[email protected]> show services security-intelligence category summary Category name :CC Status :Enable Description :Command and Control data schema Update interval :1800s TTL :3456000s Feed name :cc_domain_threatfox Version :20240218.1 Objects number:85 Create time :2024-02-18 22:06:42 UTC Update time :2024-02-19 06:43:29 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_ip_blocklist Version :20240219.1 Objects number:24821 Create time :2024-02-19 08:32:48 UTC Update time :2024-02-19 09:15:40 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_ip_data Version :20240219.10 Objects number:56839 Create time :2024-02-19 09:43:42 UTC Update time :2024-02-19 09:46:01 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_ip_dshield Version :20240219.1 Objects number:19 Create time :2024-02-19 06:05:34 UTC Update time :2024-02-19 06:44:03 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_ip_feodotracker Version :20240218.1 Objects number:14 Create time :2024-02-18 20:58:50 UTC Update time :2024-02-19 07:13:58 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_ip_threatfox Version :20240218.1 Objects number:80 Create time :2024-02-18 22:12:44 UTC Update time :2024-02-19 07:13:58 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_ip_tor Version :20240218.1 Objects number:1166 Create time :2024-02-18 14:45:04 UTC Update time :2024-02-19 07:13:58 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_url_data Version :20240219.5 Objects number:34571 Create time :2024-02-19 09:44:33 UTC Update time :2024-02-19 09:46:04 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Feed name :cc_url_threatfox Version :20240218.1 Objects number:37 Create time :2024-02-18 22:06:43 UTC Update time :2024-02-19 07:13:58 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Category name :Infected-Hosts Status :Enable Description :Host intelligence feed Update interval :60s TTL :3456000s Feed name :infected_hosts Version :20240126.1 Objects number:0 Create time :2024-01-26 06:48:40 UTC Update time :2024-02-19 06:18:09 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Category name :GeoIP Status :Enable Description :GeoIP data schema Update interval :86400s TTL :157680000s Feed name :geoip_country Version :20240217.1 Objects number:469619 Create time :2024-02-19 06:14:55 UTC Update time :2024-02-19 06:18:16 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A Category name :Blacklist Status :Enable Description :Customer category Blacklist Update interval :300s TTL :2592000s Feed name :Jtac-CustomFeed Version :1708331129.1 Objects number:9 Create time :2024-02-19 08:25:29 UTC Update time :2024-02-19 08:30:10 UTC Update status :Store succeeded Expired :No Status :Active Options :N/A