SRX340

Juniper SRX340 User guide

  • Hello! I am an AI chatbot trained to assist you with the Juniper SRX340 User guide. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
J-Web User Guide for SRX Series Devices
Published
2021-06-29
Juniper Networks, Inc.
1133 Innovaon Way
Sunnyvale, California 94089
USA
408-745-2000
www.juniper.net
Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc.
in the United States and other countries. All other trademarks, service marks, registered marks, or registered service
marks are the property of their respecve owners.
Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right
to change, modify, transfer, or otherwise revise this publicaon without noce.
J-Web User Guide for SRX Series Devices
Copyright © 2021 Juniper Networks, Inc. All rights reserved.
The informaon in this document is current as of the date on the tle page.
YEAR 2000 NOTICE
Juniper Networks hardware and soware products are Year 2000 compliant. Junos OS has no known me-related
limitaons through the year 2038. However, the NTP applicaon is known to have some diculty in the year 2036.
END USER LICENSE AGREEMENT
The Juniper Networks product that is the subject of this technical documentaon consists of (or is intended for use
with) Juniper Networks soware. Use of such soware is subject to the terms and condions of the End User License
Agreement ("EULA") posted at hps://support.juniper.net/support/eula/. By downloading, installing or using such
soware, you agree to the terms and condions of that EULA.
ii
Table of Contents
About This Guide | xxv
1
Juniper Web Device Manager
Geng Started | 2
Juniper Web Device Manager Overview | 2
What is J-Web? | 2
Benets of J-Web | 3
Start J-Web | 3
Prerequisites for Using J-Web | 3
Log On to J-Web | 4
Congure SRX Devices Using the J-Web Setup Wizard | 5
J-Web First Look | 28
Explore J-Web | 29
J-Web Launch Pad | 29
J-Web Top Pane | 30
J-Web Side Pane | 33
J-Web Main Pane | 35
J-Web Workow Wizards | 38
Summary | 39
2
Dashboard
J-Web Dashboard | 41
Dashboard Overview | 41
What is J-Web Dashboard | 41
Work with Widgets | 42
3
Monitor
Network | 50
Monitor Interfaces | 50
Monitor DHCP Server Bindings | 51
Monitor IPsec VPN | 53
iii
Logs | 59
Monitor Session | 59
Monitor Threats | 63
Monitor Web Filtering | 67
Monitor ATP | 70
Monitor VPN | 74
Monitor All Events | 77
Monitor Alarms | 83
Maps and Charts | 85
Monitor Trac Map | 85
Monitor Threats Map | 88
Monitor Applicaons | 95
Monitor Users | 99
Stascs | 101
Monitor Threat Prevenon | 101
Monitor VPN Phase I | 102
Monitor VPN Phase II | 104
Reports | 107
About Reports Page | 107
Overview | 108
Threat Assessment Report | 113
Applicaon and User Usage | 113
Top Talkers | 114
IPS Threat Environment | 114
Viruses Blocked | 115
URL Report | 115
Virus: Top Blocked | 115
Top Firewall Events | 115
Top Firewall Deny Desnaons | 116
iv
Top Firewall Denies | 116
Top IPS Events | 116
Top An-spam Detected | 116
Top Screen Aackers | 116
Top Screen Vicms | 116
Top Screen Hits | 116
Top Firewall Rules | 116
Top Firewall Deny Sources | 116
Top IPS Aack Sources | 116
Top IPS Aack Desnaons | 117
Top IPS Rules | 117
Top Web Apps | 117
Top Applicaons Blocked | 117
Top URLs by User | 117
Top Source Zone by Volume | 117
Top Applicaons by User | 117
Top Botnet Threats By Source Address via IDP Logs | 118
Top Botnet Threats by Desnaon Address via IDP Logs | 118
Top Botnet Threats by Threat Severity via IDP Logs | 118
Top Malware Threats by Source Address via IDP Logs | 118
Top Malware Threats by Desnaon Address via IDP Logs | 118
Top Malware Threats by Threat Severity via IDP Logs | 119
Top Blocked Applicaons via Weblter Logs | 119
Top Permied Applicaon Subcategories by Volume via Weblter Logs | 119
Top Permied Applicaon Subcategories by Count via Weblter Logs | 119
4
Device Administraon
Basic Sengs | 122
Congure Basic Sengs | 122
Cluster Management | 143
Congure Cluster (HA) Setup | 143
About the Cluster Conguraon Page | 159
Edit Node Sengs | 162
Add an HA Cluster Interface | 163
v
Edit an HA Cluster Interface | 165
Delete HA Cluster Interface | 165
Add a Redundancy Group | 166
Edit a Redundancy Group | 168
Delete Redundancy Group | 169
User Management | 170
About the User Management Page | 170
Add a User | 174
Edit a User | 176
Delete User | 176
Mul Tenancy—Resource Proles | 177
About the Resource Proles Page | 177
Global Sengs | 179
Add a Resource Prole | 180
Edit a Resource Prole | 184
Delete Resource Prole | 185
Mul Tenancy—Interconnect Ports | 186
About the Interconnect Ports Page | 186
Add a LT Logical Interface | 188
Edit a LT Logical Interface | 195
Delete Logical Interface | 195
Search for Text in an Interconnect Ports Table | 195
Mul Tenancy—Logical Systems | 197
About the Logical Systems Page | 197
Add a Logical System | 199
Edit a Logical System | 211
vi
Delete Logical System | 211
Search Text in Logical Systems Table | 212
Mul Tenancy—Tenants | 213
About the Tenants Page | 213
Add a Tenant | 215
Edit a Tenant | 223
Delete Tenant | 223
Search Text in Tenants Table | 224
Cercate Management—Device Cercates | 225
About the Device Cercates Page | 225
Import a Device Cercate | 227
Export a Device Cercate | 228
Add a Device Cercate | 229
Delete Device Cercate | 232
View Details of a Device Cercate | 233
Search Text in the Device Cercates Table | 237
Cercate Management—Trusted Cercate Authority | 238
About the Trusted Cercate Authority Page | 238
Generate Default Trusted Cercate Authories | 240
Enroll a CA Cercate | 241
Import a CA Cercate | 242
Add a Cercate Authority Prole | 243
Edit a Cercate Authority Prole | 248
Delete Cercate Authority Prole | 248
Search Text in the Trusted Cercate Authority Table | 249
Cercate Management—Cercate Authority Group | 251
vii
About the Cercate Authority Group Page | 251
Import a Trusted CA Group | 252
Add a CA Group | 253
Edit a CA Group | 254
Delete CA Group | 255
Search Text in the Cercate Authority Group Table | 255
License Management | 257
Manage Your Licenses | 257
About License Management Page | 257
Add License | 258
Delete Installed Licenses | 259
Update Installed Licenses | 259
Update Trial Licenses | 259
Display License Keys | 259
Download License Keys | 260
Soware Feature Licenses | 260
ATP Management | 262
Enroll Your Device with Juniper ATP Cloud | 262
About the Diagnoscs Page | 266
Operaons | 268
Maintain Files | 268
About Files Page | 268
Clean Up Files | 268
Download and Delete Files | 269
Delete Backup JUNOS Package | 271
Maintain Reboot Schedule | 272
Maintain System Snapshots | 274
Soware Management | 276
Upload Soware Packages | 276
Install Soware Packages | 277
viii
Rollback Soware Package Version | 278
Conguraon Management | 280
Manage Upload Conguraon Files | 280
Manage Conguraon History | 281
Manage Rescue Conguraon | 285
Alarm Management | 286
Monitor Chassis Alarm | 286
About Chassis Alarm Page | 286
Create Chassis Alarm Denion | 286
Edit Chassis Alarm Denion | 291
Monitor System Alarm | 292
About System Alarm Page | 292
Create System Alarm Conguraon | 292
Edit System Alarm Conguraon | 296
RPM | 297
Setup RPM | 297
View RPM | 308
Tools | 314
Troubleshoot Ping Host | 314
About Ping Host Page | 314
Troubleshoot Ping MPLS | 319
About Ping MPLS Page | 319
Troubleshoot Traceroute | 324
About Traceroute Page | 325
Troubleshoot Packet Capture | 329
About Packet Capture Page | 329
Access CLI | 337
About CLI Terminal Page | 337
View CLI Conguraon | 339
ix
About CLI Viewer Page | 339
Edit CLI Conguraon | 340
About CLI Editor Page | 340
Point and Click CLI | 341
About Point and Click CLI Page | 341
Reset Conguraon | 350
Congure Setup Wizard | 350
5
Network
Connecvity—Ports | 375
About the Ports Page | 375
Add a Logical Interface | 379
Edit a Logical Interface | 387
Delete Logical Interface | 387
Connecvity—VLAN | 388
About the VLAN Page | 388
Add a VLAN | 390
Edit a VLAN | 392
Delete VLAN | 393
Assign an Interface to VLAN | 393
Connecvity—Link Aggregaon | 395
About the Link Aggregaon Page | 395
Link Aggregaon Global Sengs | 397
Add a Logical Interface to Link Aggregaon | 398
Add a Link Aggregaon | 399
Edit an Aggregated Interface | 401
Delete Link Aggregaon | 402
Search for Text in the Link Aggregaon Table | 402
x
Connecvity—PPPoE | 403
Congure PPPoE | 403
Connecvity—Wireless LAN | 405
About the Sengs Page | 405
Create an Access Point | 407
Edit an Access Point | 408
Delete Access Point | 409
Create an Access Point Radio Seng | 409
Edit an Access Point Radio Seng | 413
Delete Access Point Radio Sengs | 414
DHCP Client | 415
About the DHCP Client Page | 415
Add DHCP Client Informaon | 416
Delete DHCP Client Informaon | 418
DHCP Server | 419
About the DHCP Server Page | 419
Add a DHCP Pool | 421
Edit a DHCP Pool | 426
Delete DHCP Pool | 426
DHCP Groups Global Sengs | 427
Add a DHCP Group | 427
Edit a DHCP Group | 428
Delete DHCP Group | 429
Firewall Filters—IPv4 | 430
About the IPv4 Page | 430
Add IPv4 Firewall Filters | 431
xi
Firewall Filters—IPv6 | 449
About the IPv6 Page | 449
Add IPv6 Firewall Filters | 450
Firewall Filters—Assign to Interfaces | 466
About the Assign to Interfaces Page | 466
NAT Policies | 468
About the NAT Policies Page | 468
Create a Source NAT | 470
Edit a Source NAT | 476
Delete Source NAT | 477
NAT Pools | 478
About the NAT Pools Page | 478
Global Opons | 480
Create a Source NAT Pool | 481
Edit a Source NAT Pool | 485
Delete Source NAT Pool | 486
Add a Desnaon NAT Pool | 486
Edit a Desnaon NAT Pool | 488
Delete Desnaon NAT Pool | 488
Desnaon NAT | 489
About the Desnaon Page | 489
Add a Desnaon Rule Set | 491
Edit a Desnaon Rule Set | 494
Delete Desnaon Rule Set | 494
Stac NAT | 496
About the Stac Page | 496
Add a Stac Rule Set | 499
xii
Edit a Stac Rule Set | 502
Delete Stac Rule Set | 502
NAT Proxy ARP/ND | 504
About the Proxy ARP/ND Page | 504
Add a Proxy ARP | 505
Edit a Proxy ARP | 507
Delete a Proxy ARP | 507
Add a Proxy ND | 508
Edit a Proxy ND | 509
Delete Proxy ND | 509
Stac Roung | 511
About the Stac Roung Page | 511
Add a Stac Route | 512
Edit a Stac Route | 514
Delete Stac Route | 514
RIP Roung | 515
About the RIP Page | 515
Add a RIP Instance | 517
Edit a RIP Instance | 519
Delete RIP Instance | 519
Edit RIP Global Sengs | 520
Delete RIP Global Sengs | 524
OSPF Roung | 525
About the OSPF Page | 525
Add an OSPF | 527
Edit an OSPF | 536
xiii
Delete OSPF | 537
BGP Roung | 538
About the BGP Page | 538
Add a BGP Group | 542
Edit a BGP Group | 548
Delete a BGP Group | 549
Edit Global Informaon | 549
Roung Instances | 555
About the Roung Instances Page | 555
Add a Roung Instance | 557
Edit a Roung Instance | 558
Delete Roung Instance | 559
Roung—Policies | 560
About the Policies Page | 560
Global Opons | 562
Add a Policy | 564
Clone a Policy | 576
Edit a Policy | 577
Delete Policy | 577
Test a Policy | 578
Roung—Forwarding Mode | 579
About the Forwarding Mode Page | 579
CoS—Value Aliases | 581
About the Value Aliases Page | 581
Add a Code Point Alias | 582
Edit a Code Point Alias | 583
xiv
Delete Code Point Alias | 584
CoS—Forwarding Classes | 585
About the Forwarding Classes Page | 585
Add a Forwarding Class | 586
Edit a Forwarding Class | 587
Delete Forwarding Class | 587
CoS Classiers | 589
About the Classiers Page | 589
Add a Classier | 591
Edit a Classier | 593
Delete Classier | 593
CoS—Rewrite Rules | 594
About the Rewrite Rules Page | 594
Add a Rewrite Rule | 595
Edit a Rewrite Rule | 597
Delete Rewrite Rule | 597
CoS—Schedulers | 599
About the Schedulers Page | 599
Add a Scheduler | 600
Edit a Scheduler | 602
Delete Scheduler | 603
CoS—Scheduler Maps | 604
About the Scheduler Maps Page | 604
Add a Scheduler Map | 605
Edit a Scheduler Map | 606
Delete Scheduler Map | 607
xv
CoS—Drop Prole | 608
About the Drop Prole Page | 608
Add a Drop Prole | 609
Edit a Drop Prole | 611
Delete Drop Prole | 611
CoS—Virtual Channel Groups | 612
About the Virtual Channel Groups Page | 612
Add a Virtual Channel | 613
Edit a Virtual Channel | 615
Delete Virtual Channel | 615
CoS—Assign To Interface | 616
About the Assign To Interface Page | 616
Edit a Port | 618
Add a Logical Interface | 619
Edit a Logical Interface | 620
Delete Logical Interface | 621
Applicaon QoS | 622
About the Applicaon QoS Page | 622
Add an Applicaon QoS Prole | 625
Edit an Applicaon QoS Prole | 627
Clone an Applicaon QoS Prole | 628
Delete Applicaon QoS Prole | 628
Add a Rate Limiter Prole | 629
Edit a Rate Limiter Prole | 630
Clone a Rate Limiter Prole | 630
Delete Rate Limiter Prole | 631
xvi
IPsec VPN | 632
About the IPsec VPN Page | 632
IPsec VPN Global Sengs | 635
Create a Site-to-Site VPN | 638
Create a Remote Access VPN—Juniper Secure Connect | 657
Create a Remote Access VPN—NCP Exclusive Client | 678
Edit an IPsec VPN | 692
Delete an IPsec VPN | 694
Manual Key VPN | 695
About the Manual Key VPN Page | 695
Add a Manual Key VPN | 696
Edit a Manual Key VPN | 699
Delete Manual Key VPN | 700
Dynamic VPN | 701
About the Dynamic VPN Page | 701
Global Sengs | 703
IPsec Template | 705
Add a Dynamic VPN | 706
Edit a Dynamic VPN | 708
Delete Dynamic VPN | 708
6
Security Policies and Objects
Security Policies | 710
About the Security Policies Page | 710
Global Opons | 716
Add a Rule | 719
Clone a Rule | 734
xvii
Edit a Rule | 734
Delete Rules | 735
Zones/Screens | 736
About the Zones/Screens Page | 736
Add a Zone | 738
Edit a Zone | 741
Delete Zone | 741
Add a Screen | 742
Edit a Screen | 754
Delete Screen | 755
Zone Addresses | 756
About the Zone Addresses Page | 756
Add Zone Addresses | 758
Clone Zone Addresses | 760
Edit Zone Addresses | 761
Delete Zone Addresses | 761
Search Text in a Zone Addresses Table | 762
Global Addresses | 763
About the Global Addresses Page | 763
Add an Address Book | 764
Edit an Address Book | 768
Delete Address Book | 768
Services | 769
About the Services Page | 769
Add a Custom Applicaon | 771
Edit a Custom Applicaon | 774
xviii
Delete Custom Applicaon | 775
Add an Applicaon Group | 775
Edit an Applicaon Group | 776
Delete Applicaon Group | 777
Dynamic Applicaons | 778
About the Dynamic Applicaons Page | 778
Global Sengs | 781
Add Applicaon Signatures | 784
Clone Applicaon Signatures | 789
Add Applicaon Signatures Group | 790
Edit Applicaon Signatures | 791
Delete Applicaon Signatures | 792
Search Text in an Applicaon Signatures Table | 793
Applicaon Tracking | 794
About the Applicaon Tracking Page | 794
Schedules | 796
About the Schedules Page | 796
Add a Schedule | 798
Clone a Schedule | 800
Edit a Schedule | 801
Delete Schedule | 801
Search Text in Schedules Table | 802
Proxy Proles | 803
About the Proxy Proles Page | 803
Add a Proxy Prole | 805
Edit a Proxy Prole | 806
xix
Delete Proxy Prole | 806
7
Security Services
UTM Default Conguraon | 810
About the Default Conguraon Page | 810
Edit a Default Conguraon | 812
Delete Default Conguraon | 812
UTM Anvirus Proles | 814
About the Anvirus Proles Page | 814
Add an Anvirus Prole | 816
Clone an Anvirus Prole | 822
Edit an Anvirus Prole | 823
Delete Anvirus Prole | 823
UTM Web Filtering Proles | 825
About the Web Filtering Proles Page | 825
Add a Web Filtering Prole | 827
Clone a Web Filtering Prole | 833
Edit a Web Filtering Prole | 834
Delete Web Filtering Prole | 835
UTM Web Filtering Category Update | 836
About the Category Update Page | 836
Category Update Sengs | 838
Download and Install Sengs | 841
UTM Anspam Proles | 842
About the Anspam Proles Page | 842
Add an Anspam Prole | 844
Clone an Anspam Prole | 846
Edit an Anspam Prole | 846
xx
/