Description

This article will help you to configure and view cloud DAG feeds via PE

Symptoms

Cloud DAG Feeds are not visible on managed SRX devices. 

Solution

Cloud Feeds configuration:

Pre-requisites:

1. Security Director server should be allowed to contact the following hosts for registering the SKY ATP Realm.  Allow based on which region you would be registering the SKY ATP realm.
  • amer.sky.junipersecurity.net (North America)
  • euapac.sky.junipersecurity.net (Europe)
  • apac.sky.junipersecurity.net ( Asia Pacific)

2. Allow the Policy Enforcer to reach out to the following servers for completing the enrollment, registration into SKY ATP.  Select the right list based on the region.

North America Region

  • amer.sky.junipersecurity.net
  • va.junipersecurity.net
  • ca.junipersecurity.net
  • cloudfeeds.sky.junipersecurity.net

European Region

  • euapac.sky.junipersecurity.net
  • va.junipersecurity.net
  • ca.junipersecurity.net
  • cloudfeeds.sky.junipersecurity.net

Asia Pacific Region

  • apac.sky.junipersecurity.net
  • cloudfeeds-tokyo.sky.junipersecurity.net
  • cloudfeeds.sky.junipersecurity.net
  • va.junipersecurity.net
  • ca.junipersecurity.net:8080
 

3. Check the software on the SRX device to confirm if that matches the version that supports Security Intelligence.

 - show version
 - show configuration services security-intelligence
 

4. Deploy the Policy Enforcer VM. Refer to the link below for more details about PE VM deployment and cloud Feeds overview 

https://www.juniper.net/techpubs/en_US/release-independent/policy-enforcer/topics/task/installation/policy-enforcer-vm-config.html

https://www.juniper.net/techpubs/en_US/release-independent/policy-enforcer/topics/concept/junos-space-policy-enforcer-cloud-feeds-setup-overview.html

 

5. Login to Security Director.

a) Configure PE using Administration -> PE Settings.

image.png

NOTE: Please ensure you select the right “Threat Prevention Type”. If you select “Could Feeds Only” you can select other “Threat Prevention Types” but if you select “SKY ATP with PE” you cannot go back to “Cloud Feeds only”. In that case, you will need to rebuild the policy enforcer.

 

b) Successful message is received once the PE is configured.

image.png

Note: You can use Guided setup which will help you with every steps or you can with each steps one by one by selecting cancel button 


c) Select Configure -> Threat Prevention -> Feed Source -> Sky ATP Realms

image.png


d) Once the Sky ATP realm is added, click on the “Add Devices” link to add the devices that would need the cloud feeds to be configured.

image.png

e) Once devices are added, add a Threat prevention policy to configure the “Command and Control” feeds.
image.png


f) Once the Threat prevention policy is configured, the connector is setup. Now use this Threat prevention policy in a firewall policy.

image.png


g) Publish and Update the firewall policy to the device.
 

h) Make sure Cloud feed is enabled over SKY ATP portal and reflected under shared -> address objects page over SD UI. 

1) Login to SKY ATP portal and enable required cloud DAG feed for example: office365, Zscaler etc 

image.png

image.png

i) Include the required DAG objects to firewall rules as per requirement and perform publish/update on the managed SRX device. 

image.png

j) After successful update operation, device should show the cloud DAG feed

 

Device Validation:

Once the device and PE is configured, please check the following values to confirm if the connectivity is fine on the SRX and PE

SRX => PE 443, Internet 80,8080,443

Please find below URL for PE ports details 
https://www.juniper.net/documentation/us/en/software/nm-apps23.1/policy-enforcer-user-guide/topics/concept/policy-enforcer-ports.html

Note: If we are using SDI as Policy enforcer then port might be different then legacy PE, please refer SDI-PE user guide for the same. 

[email protected]> show version
Hostname: vSRX-23.4R1.9
Model: vSRX
Junos: 23.4R1.9

SecIntel Check: The configuration below shows the association to Policy Enforcer.

[email protected]> show configuration services security-intelligence | display set | no-more
set services security-intelligence url https://10.219.87.34:443/api/v1/manifest.xml
set services security-intelligence authentication auth-token KZUX03ZI6AJ577C9UUPXM423A1QXYBS4

Check if feeds are downloaded using the following commands:

[email protected]> show services security-intelligence update status
Current action        :Checking update interval of category GeoIP.
Last update status    :Update interval of category CC is not reached.
Last connection status:succeeded
Last update time      :2024-02-19 09:57:16 UTC    

[email protected]> request services security-intelligence download status
Security intelligence feed download status:
Start time:Mon Feb 19 06:13:06 2024
Start downloading the latest manifest.
Start parsing manifest file.
Parse manifest succeeded, version:f247934317b59e2cf9e82e942d21497c.
End time:Mon Feb 19 06:13:06 2024

[email protected]> show security dynamic-address address-name ?
Possible completions:
  <address-name>       Dynamic address name
  JTAC-GeoIP           
  ipfilter_cloudflare  
  ipfilter_facebook    
  ipfilter_office365   
  ipfilter_paypal      
  ipfilter_sdcloud     
  ipfilter_zscaler     

[email protected]> show security dynamic-address address-name ipfilter_office365 
No.     IP-start             IP-end               Feed             Address           
1       13.107.6.152         13.107.6.153         IPFilter/ipfilter_office365 ipfilter_office365
2       13.107.6.171         13.107.6.171         IPFilter/ipfilter_office365 ipfilter_office365
3       13.107.6.192         13.107.6.192         IPFilter/ipfilter_office365 ipfilter_office365
4       13.107.9.192         13.107.9.192         IPFilter/ipfilter_office365 ipfilter_office365
5       13.107.18.10         13.107.18.11         IPFilter/ipfilter_office365 ipfilter_office365
6       13.107.18.15         13.107.18.15         IPFilter/ipfilter_office365 ipfilter_office365
7       13.107.64.0          13.107.127.255       IPFilter/ipfilter_office365 ipfilter_office365

[email protected]> show security dynamic-address category-name CC
No.     IP-start             IP-end               Feed                             Address                       CountryCode

1       1.0.4.1              1.0.4.1              CC/3                             ID-fffc0831                      --                      
2       1.0.5.1              1.0.5.1              CC/3                             ID-fffc0831                      --                      
3       1.0.6.1              1.0.6.1              CC/3                             ID-fffc0831                      --                      
4       1.0.7.1              1.0.7.1              CC/3                             ID-fffc0831                      --                      
5       1.0.16.1             1.0.16.1             CC/3                             ID-fffc0831                      --                      
6       1.0.32.1             1.0.32.1             CC/3                             ID-fffc0831                      --   
                                                                               
The end octet of the address entry “ID-fffc0831” would indicate the threat level of the address.

 

Run the command below to list all the feed categories downloaded to the SRX device:

[email protected]> show services security-intelligence category summary
Category name     :CC
  Status          :Enable
  Description     :Command and Control data schema
  Update interval :1800s
  TTL             :3456000s

  Feed name       :cc_domain_threatfox
    Version       :20240218.1
    Objects number:85
    Create time   :2024-02-18 22:06:42 UTC
    Update time   :2024-02-19 06:43:29 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

  Feed name       :cc_ip_blocklist
    Version       :20240219.1
    Objects number:24821
    Create time   :2024-02-19 08:32:48 UTC
    Update time   :2024-02-19 09:15:40 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

  Feed name       :cc_ip_data
    Version       :20240219.10
    Objects number:56839
    Create time   :2024-02-19 09:43:42 UTC
    Update time   :2024-02-19 09:46:01 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

  Feed name       :cc_ip_dshield
    Version       :20240219.1
    Objects number:19
    Create time   :2024-02-19 06:05:34 UTC
    Update time   :2024-02-19 06:44:03 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

  Feed name       :cc_ip_feodotracker
    Version       :20240218.1
    Objects number:14
    Create time   :2024-02-18 20:58:50 UTC
    Update time   :2024-02-19 07:13:58 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

  Feed name       :cc_ip_threatfox
    Version       :20240218.1
    Objects number:80
    Create time   :2024-02-18 22:12:44 UTC
    Update time   :2024-02-19 07:13:58 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

  Feed name       :cc_ip_tor
    Version       :20240218.1
    Objects number:1166
    Create time   :2024-02-18 14:45:04 UTC
    Update time   :2024-02-19 07:13:58 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

  Feed name       :cc_url_data
    Version       :20240219.5
    Objects number:34571
    Create time   :2024-02-19 09:44:33 UTC
    Update time   :2024-02-19 09:46:04 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A
  Feed name       :cc_url_threatfox
    Version       :20240218.1
    Objects number:37
    Create time   :2024-02-18 22:06:43 UTC
    Update time   :2024-02-19 07:13:58 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

Category name     :Infected-Hosts
  Status          :Enable
  Description     :Host intelligence feed
  Update interval :60s
  TTL             :3456000s
  Feed name       :infected_hosts
    Version       :20240126.1
    Objects number:0
    Create time   :2024-01-26 06:48:40 UTC
    Update time   :2024-02-19 06:18:09 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

Category name     :GeoIP
  Status          :Enable
  Description     :GeoIP data schema
  Update interval :86400s
  TTL             :157680000s
  Feed name       :geoip_country
    Version       :20240217.1
    Objects number:469619
    Create time   :2024-02-19 06:14:55 UTC
    Update time   :2024-02-19 06:18:16 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A

Category name     :Blacklist
  Status          :Enable
  Description     :Customer category Blacklist
  Update interval :300s
  TTL             :2592000s
  Feed name       :Jtac-CustomFeed
    Version       :1708331129.1
    Objects number:9
    Create time   :2024-02-19 08:25:29 UTC
    Update time   :2024-02-19 08:30:10 UTC
    Update status :Store succeeded
    Expired       :No
    Status        :Active
    Options       :N/A
 
Note : If you face any issues, please contact JUNIPER JTAC Support for assistance.

Modification History

Article Published: 19 Feb 2024