Description


This article describes a way to configure/enable IDP (Intrusion Detection and Prevention) features in the SSR series device deployed in the SDWAN solution.



Solution

 

Intrusion Detection and Prevention (IDP) leverages the Juniper IDP Signature Database, providing state of the art protection against the most up-to-date vulnerabilities. The database contains definitions of attack objects and application signatures defined in the form of an IDP policy ruleset that is updated regularly. By automatically downloading the latest definitions and application signatures, the SSR is able to provide cutting edge security solutions for your network.

 

In a typical network deployment, there is always a mix of trusted and untrusted traffic. To prevent against security breaches, the SSR uses the IDP Signature database to identify and take action against malicious traffic. SSR services are configured to be monitored, and an IDP policy is applied to the traffic.

The idp-policy has three profiles that can be applied to an access-policy; Alert, Standard, and Strict. This allows the same service to receive different IDP treatment for different tenants. Each profile has an associated traffic action that may include all or some of the following actions:

  • Close the client and server TCP connection.
  • Drop current and all subsequent packets.
  • Alert only, no additional action taken.

 

From the GUI, you can configure:

 

The following steps show how to use the GUI to use an existing IDP policy to create a modified IDP Profile.

 

  1. Navigate to the IDP Profile feature.

 

 

2. Click ADD.

3. Enter a Profile Name and click Save. The IDP Profiles configuration screen opens. 

 

Configure the IDP Profile

 

4. In the Base Policy, select an existing policy to modify.

5. To add exceptions to the rules, select ADD in the Rules field.

6. Name the New item and click Save. This opens the settings for the new rule.

7. Identify the following items that will be compared for a match:

 

NOTE: The information available on the Security Events screen or the show idp-events command can be used to populate and modify the Rules fields shown below.

  • Client IP Address prefix
  • Destination IP Address
  • Vulnerability
  • Severity
  • Action Options

 

Please refer for more details: 

Configure Intrusion Detection and Prevention

Troubleshooting IDP

Modification History

2024-12-17 : Article Created

Related Information

Configure Intrusion Detection and Prevention

Troubleshooting IDP