04-13-2012 12:41 PM
Hello Everyone,
I believe that the AppSecure feature in the SRX firewalls is a game changing for Juniper.
However, I can not seem to get it working properly, especially with Skype, Ultraserve, and Hotshield. Did anyone come across such implementation and succeded?
Also, can I create a custom application signature? How to do so if possible?
Thanks in advance ![]()
04-19-2012 02:04 AM
Guys! Any help will be appreciated!!!
04-19-2012 06:18 AM
04-20-2012 05:11 AM
Hello,
Keep dreaming of you want the same feature set like Palo Alto in this area...
PS : It seems that Juniper put AppSecure on top of IDP which is already a nightmare.
PS : As far as I kown, Appsecure is NOT supported on low end (including SRX 240) platform.
Hegards,
Hedi
04-22-2012 01:32 AM
Thank you very much Ron for your reply. I was actually able to block http and ftp ONLY, which is surprising that Juniper would make such a fuzz out of something that is not working properly! Do you know if the AppSecure works properly on the Highend models (1400, 3000s, and 5000s)?
04-22-2012 01:35 AM
Hedia,
That is very frustrating man, but AppSecure is "officially" supported on the branch models (100, 200, 500, 600s), it is on the pricelist and they issued a datasheet for it too (http://www.juniper.net/elqNow/elqRedir.htm?ref=htt
Thanks anyway...
04-22-2012 01:19 PM
04-22-2012 07:13 PM
khaled.kamal wrote:I was actually able to block http and ftp ONLY
Can you elaborate? Do you mean all the AppFW policies only work on port 80 and 21? We are looking at the SRX line and at this point we are getting very gunshy as it seems everyone here hates them. I've seen only a fwe positive responses and it's only when you are doing basic port firewalling. We've got that now with our ASAs.
Our initial thoughts were keeping SSL VPN, NAC and Firewall all Juniper would allow us to do some really slick rules across devices, but now I am thinking SSL VPN and NAC may be the limit of what we want to integrate.
04-23-2012 02:36 AM
05-03-2012 05:54 AM
jspanitz wrote:
khaled.kamal wrote:I was actually able to block http and ftp ONLY
Can you elaborate? Do you mean all the AppFW policies only work on port 80 and 21?
I mean when I apply AppFW on "Junos-http" or "Junos-ftp" it actually blocks all the http and all the ftp traffic. However, any other application block rule does not block that specific application. For example and this is really basic, blocking the video streaming does not work. Blocking the "Skype" also does not work...!!!
I can't believe that this is it for Juniper, how can I buy AppSecure license and not get my money value for that!!!!
I have been trying Cyberoam for Application blocking, and it is surprisingly working just fine till now! Did anyone tried Cyberoam?