Chapter 4 Resetting the SRX Series Device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Resetting the Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Resetting Your Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Resetting Your SRX Series to a Rescue Configuration . . . . . . . . . . . . . . . 27
Resetting Your SRX Series to Factory Settings . . . . . . . . . . . . . . . . . . . . . 27
Part 3 Configuring Basic SRX Series Features
Chapter 5 Configuring Security Zones and Policies for SRX Series . . . . . . . . . . . . . . . . . 31
Understanding Security Zones and Policies for SRX Series . . . . . . . . . . . . . . . . . . 31
Zones . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31
Security Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Example: Configuring Security Zones and Policies for SRX Series . . . . . . . . . . . . . 32
Chapter 6 Configuring NAT for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
Understanding NAT for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
Example: Configuring Destination NAT for SRX Series . . . . . . . . . . . . . . . . . . . . . 40
Chapter 7 Managing Licenses for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Updating Licenses for a Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Chapter 8 Configuring UTM for Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
Understanding Unified Threat Management for Branch SRX Series . . . . . . . . . . . 49
Example: Configuring Unified Threat Management for a Branch SRX Series . . . . . 51
Default UTM Policy for Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
Default UTM Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
Predefined UTM Profile Configuration for Branch SRX Series . . . . . . . . . . . . . . . . 54
Antispam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
Antivirus . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
Web Filtering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
Chapter 9 Configuring Intrusion Detection and Prevention for SRX Series . . . . . . . . . 63
Understanding Intrusion Detection and Prevention for SRX Series . . . . . . . . . . . . 63
Example: Configuring Intrusion Detection and Prevention for SRX Series . . . . . . 64
Chapter 10 Understanding Stateful Firewall, IPsec VPN, and Chassis Cluster for
Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71
Understanding Branch SRX Series Stateful Firewall Functionality . . . . . . . . . . . . . 71
Understanding IPsec VPN for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
Understanding Chassis Cluster for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
Part 4 Configuration Statements and Operational Commands
Chapter 11 Configuration Statements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
Security Configuration Statement Hierarchy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
[edit security address-book] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
[edit security idp] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77
[edit security ike] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87
[edit security ipsec] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88
[edit security nat] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90
[edit security policies] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93
Copyright © 2016, Juniper Networks, Inc.iv
Getting Started Guide for Branch SRX Series