Security

last person joined: 6 days ago 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  NSM - is it possible to apply SSG policy on an SRX device?

    Posted 09-01-2014 04:36

    Hello,

     

    I'm replacing my SSG-HA, which is currntly managed by NSM 2009, with an SRX cluster, which is managed by another NSM 2012.2.

    I would like to use my current policy, on my new SRX cluster.

     

    is it possible?

    if so, can someone, please, point me to a good procedure? i couldn't find one...

     

    Many thanks,

    Ohad

     



  • 2.  RE: NSM - is it possible to apply SSG policy on an SRX device?
    Best Answer

    Posted 09-01-2014 05:58

    Yes, the policy management section of NSM can be pushed to either SRX or SSG devices.  But there are some features that are specific to the platforms that would need to be converted.

     

    I have a number of policies that either migrated to Junos or have a mix of SSG and SRX with the same rule set applied.  You just need to avoid nat and build out the rest of the policy to be compatible for either OS.

     

    Unfortunately, I've not located any documentation on this.

     

    If you have a lot of changes for these differences, I would use the save as to make a copy of the existing policy to modify so that roll back is easier and testing in advance possible.

     

    Differences:

     

    NAT - All your NAT rules need to be removed for the SSG policy and created as a nat tab for the SRX.  You may still need the security rule if the traffic is not permited by some other rule.  The dffierence is that in ScreenOS your nat and security policy are on the same rule.  In Junos they are in different tabs and rules.  Junos nat rules also have a limit of 8 address objects and no groups.  So you may need more rules with these limits.  VIP, MIP and DIP all need to be converted.

     

    Multi-service objects - there are a few service objects in screenOS that have a single service object with multiple ports on the object.  These will show up in Junos as ONLY the first port.  You will need to convert these to service groups.

     

    Service custom time outs - In NSM the custom time out for Junos and ScreenOS are in different sections of your custom services.  You need to fill in both.  Also note that one is in seconds and the other in minutes so they are different numbers.



  • 3.  RE: NSM - is it possible to apply SSG policy on an SRX device?

    Posted 09-07-2014 01:30

    Many Thanks.