Job Type: Execute RPC, which says 'Success'; however, device enrollment will get failed which can be seen under Job Result
Job Result:
<output xmlns:junos="http://xml.juniper.net/junos/22.4R0/junos">Platform is supported by ATP Cloud: VSRX.</output> <output>Version 22.4R2.8 is valid for bootstrapping.</output> <output>License found with name: ATP Cloud.</output> <output>Enrolling with ATP Cloud license serial number: 060xxxxxxx5-qxxC1.</output> <output>Going to enroll single device for VSRX: 3025FBxxxxFF@06032xxxxx05-qxxxC1 with hostname vSRX-22.4R2.8.</output> <output>Application Signature DB version on this device is: 3720. Using latest version of Application Signature DB is recommended.</output> <output>Communicate with cloud...</output> <output>License type for this device: premium.</output> <output>License of your device will expire in 364 days.</output> <output>Remove related security-intelligence service configurations...</output> <output>Remove related advanced-anti-malware service configurations...</output> <output>Remove related SSL service configurations...</output> <output>Remove related PKI configurations...</output> <output>Clear local certificate aamw-srx-cert...</output> <output>Clear key pair: aamw-srx-cert...</output> <output>Clear CA profile aamw-cloud-ca...</output> <output>Clear CA profile aamw-secintel-ca...</output> <output>Configure CA...</output> <output>Request aamw-secintel-ca CA...</output> <output>Wait aamw-secintel-ca CA download status...</output> <output>Load aamw-secintel-ca CA...</output> <output>Request aamw-cloud-ca CA...</output> <output>Wait aamw-cloud-ca CA download status...</output> <output>Load aamw-cloud-ca CA...</output> <output>Retrieve CA profile aamw-ca...</output> <output>CA certificate ready: aamw-ca...</output> <output>CA certificate ready: aamw-cloud-ca...</output> <output>CA certificate ready: aamw-secintel-ca...</output> <output>Generate key pair: aamw-srx-cert...</output> <output>Enroll local certificate aamw-srx-cert with CA server...</output> <xnm:error xmlns:xnm="http://xml.juniper.net/xnm/1.1/xnm"> <source-daemon>op-script</source-daemon> <message>[Error] Enrollment failed. Fail to set client certificate aamw-srx-cert with time issues. Setting device time correctly will resolve this issue. Please run diagnostic process. Please run diagnostic process with the following cli command: request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail pre-detection</message> </xnm:error> <xnm:error xmlns:xnm="http://xml.juniper.net/xnm/1.1/xnm"> <source-daemon>op-script</source-daemon> <message></message> </xnm:error>
Below output can be seen on the device
[email protected]> request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail pre-detection [INFO] Try to get IP address for hostname srxapi.ap-northeast-1.sky.junipersecurity.net DNS check : [OK] [INFO] Try to test Juniper ATP server connectivity [INFO] Successfully connected to srxapi.ap-northeast-1.sky.junipersecurity.net:443 [INFO] Successfully connected to ca.junipersecurity.net:8080 [INFO] Successfully connected to va.junipersecurity.net:80 Juniper ATP reachability check : [OK] [INFO] Time difference between ATP server and this device: 1358 second(s) Time check : [Failure] Error: Time difference is too large between server and this device. Please adjust your local time [INFO] Configuration checking passed: PKI [INFO] Configuration checking passed: SSL [INFO] Configuration checking passed: AAMW Connection [INFO] Configuration checking passed: SecIntel URL [INFO] Configuration checking passed: SecIntel Authentication Configuration activation check : [OK] [INFO] Try ICMP service in Juniper ATP Juniper ATP ICMP service check : [OK] [INFO] To-ATP connection is using ge-0/0/0.0, according to route Interface configuration check : [OK] Outgoing interface MTU is default value [INFO] Check IP MTU with length 1472 [INFO] Check IP MTU with length 864 [INFO] Check IP MTU with length 560 [INFO] Check IP MTU with length 408 [INFO] Check IP MTU with length 332 [INFO] Check IP MTU with length 294 [INFO] Check IP MTU with length 275 [INFO] Check IP MTU with length 265 [INFO] Check IP MTU with length 260 [INFO] Check IP MTU with length 258 [INFO] Check IP MTU with length 257 Warning: Outgoing interface MTU larger than path MTU IP Path MTU is 256 [INFO] VSRX detected. Checking system licenses VSRX License check : [OK] [email protected]> show system uptime Current time: 2024-07-09 06:34:56 UTC Time Source: LOCAL CLOCK System booted: 2024-06-16 02:40:29 UTC (3w2d 03:54 ago) Protocols started: 2024-06-16 02:42:05 UTC (3w2d 03:52 ago) Last configured: 2024-07-09 06:29:44 UTC (00:05:12 ago) by root 6:34AM up 23 days, 3:54, 1 users, load averages: 0.60, 1.49, 3.86
Below Output can be seen on SD-PE
# mysql -uroot -pmariadb -A feeder -e "select * from device where name='vSRX-22.4R2.8' \G;" *************************** 1. row *************************** id: 0934a635-2831-4e44-ac06-d38e7f3a2f2a emsId: 12 emsSdId: 1998848 lsysDevice: 0 lsysRootDeviceEmsId: 12 lsysRootDeviceEmsSdId: 1998848 name: vSRX-22.4R2.8 description: NULL domain: NULL feedSourceId: 7971b4a0-9197-4ae5-952d-d9fb509e56a6 ip: 10.x.x.x model: VSRX serialNumber: 3025FBBA6CFF secondarySerialNumber: NA cluster: 0 createTs: 1720507871 updateTs: 1720508137 initStatus: FAILURE enrollStatus: ENROLL_FAILURE feedSourceConfigStatus: NULL initStatusReason: Sky Enrollment Failed enrollFailureDetails: ['[Error] Enrollment failed. Fail to set client certificate aamw-srx-cert with time issues. Setting device time correctly will resolve this issue. Please run diagnostic process.', 'Please run diagnostic process with the following cli command:', ' request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail pre-detection', 'None'] connectorId: NULL perimeterDevice: 1
Step 1: To set/change clock or NTP settings follow KB15756 [juniper.net]
After updating/changing the timestamp verify the same on device
Example: [email protected]> show system uptime Current time: 2024-07-09 07:01:54 UTC Time Source: NTP CLOCK System booted: 2024-06-16 03:04:19 UTC (3w2d 03:57 ago) Protocols started: 2024-06-16 03:05:56 UTC (3w2d 03:55 ago) Last configured: 2024-07-09 07:01:47 UTC (00:00:07 ago) by root 7:01AM up 23 days, 3:58, 1 users, load averages: 0.93, 1.24, 3.28
Step 2: Now need to enrol device back under secure fabric by following below steps.
a) SD UI > Devices > Secure Fabric > Sites > Unselect the affected device -> click ok, then it will create Execute RPC job which will be visible under Job Management.
b) SD UI > Devices > Secure Fabric > Sites > select the affected device > click ok, then it will create Execute RPC job which will be visible under Job Management and Make sure device enrolment is successful
Job Type: Execute RPC
<output xmlns:junos="http://xml.juniper.net/junos/22.4R0/junos">Platform is supported by ATP Cloud: VSRX.</output> <output>Version 22.4R2.8 is valid for bootstrapping.</output> <output>License found with name: ATP Cloud.</output> <output>Enrolling with ATP Cloud license serial number: 060320xxxxxx-qu4C1.</output> <output>Going to enroll single device for VSRX: 3025xxxxxCFF@06032xxxx05-qu4C1 with hostname vSRX-22.4R2.8.</output> <output>Application Signature DB version on this device is: 3720. Using latest version of Application Signature DB is recommended.</output> <output>Communicate with cloud...</output> <output>License type for this device: premium.</output> <output>License of your device will expire in 364 days.</output> <output>Remove related security-intelligence service configurations...</output> <output>Remove related advanced-anti-malware service configurations...</output> <output>Remove related SSL service configurations...</output> <output>Remove related PKI configurations...</output> <output>Clear local certificate aamw-srx-cert...</output> <output>Clear key pair: aamw-srx-cert...</output> <output>Clear CA profile aamw-cloud-ca...</output> <output>Clear CA profile aamw-secintel-ca...</output> <output>Configure CA...</output> <output>Request aamw-secintel-ca CA...</output> <output>Wait aamw-secintel-ca CA download status...</output> <output>Load aamw-secintel-ca CA...</output> <output>Request aamw-cloud-ca CA...</output> <output>Wait aamw-cloud-ca CA download status...</output> <output>Load aamw-cloud-ca CA...</output> <output>Retrieve CA profile aamw-ca...</output> <output>CA certificate ready: aamw-ca...</output> <output>CA certificate ready: aamw-cloud-ca...</output> <output>CA certificate ready: aamw-secintel-ca...</output> <output>Generate key pair: aamw-srx-cert...</output> <output>Enroll local certificate aamw-srx-cert with CA server...</output> <output>Configure SSL service...</output> <output>Configuration added successfully for SSL service.</output> <output>Configure advanced-anti-malware service...</output> <output>Configuration added successfully for advanced-anti-malware service.</output> <output>Configure security-intelligence service...</output> <output>Configuration added successfully for security-intelligence service.</output> <output>Check configuration on device...</output> <output>SSL profile: [OK]</output> <output>SecIntel CA: [OK]</output> <output>Cloud CA: [OK]</output> <output>Client cert found: [OK]</output> <output>SSL profile action: [OK]</output> <output>URL for advanced-anti-malware: [OK]</output> <output>Profile for advanced-anti-malware: [OK]</output> <output>URL for security-intelligence: [OK]</output> <output>Profile for security-intelligence: [OK]</output> <output>All configurations are correct for enrollment.</output> <output>Communicate with cloud...</output> <output>Wait for aamw connection status...</output> <output>Device enrolled successfully!</output> <output>Please see following links for more information:</output> <output>ATP Cloud sample config: https://www.juniper.net/documentation/en_US/release-independent/sky-atp/topics/example/configuration/sky-atp-policy-creating-cli.html</output> <output>ATP Cloud quick start guide: http://www.juniper.net/documentation/en_US/release-independent/sky-atp/information-products/topic-collections/sky-atp-qsg.pdf</output> <output>ATP Cloud technical documents: http://www.juniper.net/documentation/en_US/release-independent/sky-atp/information-products/pathway-pages/index.html</output> <output>It is recommended to run diagnostic process with the following cli command to make sure all configurations are valid: request services advanced-anti-malware diagnostics srxapi.ap-northeast-1.sky.junipersecurity.net detail</output>
Note : If you face any issues, please contact JUNIPER JTAC Support for assistance.