SRX Services Gateway
Reply
Contributor
ABC-TECH
Posts: 20
Registered: ‎05-31-2009
0
Accepted Solution

Time based website restriction on SRX 210

Dears,

 

Can SRX 210 with WF subscription can restrict some sites based on specific time of day.

also can SRX restrict download sizes above a specific size.

 

How can this be done , or point me to any good Documentation for UTM features for SRX.

 


Aji

Super Contributor
colemtb
Posts: 313
Registered: ‎09-30-2009

Re: Time based website restriction on SRX 210

You could use a simple scheduler on policy and in your permit statement reference the UTM WF policy.  This would require UTM subscribption, not sure on filesize off the top of my head though.

Contributor
ABC-TECH
Posts: 20
Registered: ‎05-31-2009
0

Re: Time based website restriction on SRX 210

Can you make it more elaborate how to make this work. any document which you can point me to ?

Distinguished Expert
muttbarker
Posts: 2,389
Registered: ‎01-29-2008

Re: Time based website restriction on SRX 210

It is a two part process - you define schedules and then apply that schedule to a policy. To define a schedule you use the following command:

 

set schedulers scheduler name dayOfWeek start-time stop-time

 

So for example if you want a schedule to be active every day from 8 to 5 you would do:

 

set schedulers schedule allow-web daily start-time 08:00 stop-time 17:00

 

You then create your policy and apply the scheduler to that policy. The policy is then "active" during the scheduled time period.

 

set security policies from-zone trust to zone untrust policy  allow-web-out match source-..........

set security policies from-zone trust to zone untrust policy  allow-web-out match destination-.....

set security policies from-zone trust to zone untrust policy  allow-web-out match application ..........

set security policies from-zone trust to zone untrust policy  allow-web-out then permit

set security policies from-zone trust to zone untrust policy  allow-web-out scheduler name allow-web

Kevin Barker
JNCIP-SEC
JNCIS-ENT, FWV, SSL, WLAN
JNCIA-ER, EX, IDP, UAC, WX
Juniper Networks Certified Instructor
Juniper Networks Ambassador

Juniper Elite Reseller
J-Partner Service Specialist - Implementation

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.