Disabling a Rule . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 517
Using Rule Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 517
Reimporting Devices and Security Policies . . . . . . . . . . . . . . . . . . . . . . . . . . 518
Merging Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 518
Importing SRX Series Devices That Contain Inactive Policies . . . . . . . . . . . 520
Exporting Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 520
Automatic Policy Versioning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 521
Setting NSM to Automatic Policy Versioning . . . . . . . . . . . . . . . . . . . . . 521
Viewing Existing Policy Versions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 522
Creating a New Policy Version . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 522
Using a Filter to Search for a Policy Version . . . . . . . . . . . . . . . . . . . . . . 523
Editing Comments for an Existing Policy Version . . . . . . . . . . . . . . . . . . 523
Comparing Two Versions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 523
Restore an Older Version . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 524
Viewing, Editing, Filtering, and Sorting Database Versions . . . . . . . . . . 524
Displaying the Differences Between Database Versions . . . . . . . . . . . . 525
Update Device with an Older Database Version . . . . . . . . . . . . . . . . . . 526
Pre and Post Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 526
Rule Application Sequence . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 528
ScreenOS Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 528
Validation of prerules and postrules . . . . . . . . . . . . . . . . . . . . . . . . . . . . 528
Install-On Column for prerules and postrules . . . . . . . . . . . . . . . . . . . . 528
Managing prerules and postrules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 529
Add prerules and postrules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 529
Push prerules and postrules to Regional Server . . . . . . . . . . . . . . . . . . . 529
Modify prerules and postrules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 529
Delete prerules and postrules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 530
Polymorphic Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 530
Customizing Polymorphic Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 530
Access Control of Polymorphic Object . . . . . . . . . . . . . . . . . . . . . . . . . . 531
Validation of Polymorphic Object . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 531
Supported Polymorphic Object Categories . . . . . . . . . . . . . . . . . . . . . . . 531
Manage Polymorphic Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 531
Create a Polymorphic Object . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 532
Add a Polymorphic Object to a Pre/Post Rule . . . . . . . . . . . . . . . . . . . . 532
Map a Polymorphic Object to a Real Value . . . . . . . . . . . . . . . . . . . . . . 533
Mapping Polymorphic Objects Before Importing or Updating Affected
Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 533
Chapter 10
Configuring Voice Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 535
Adding a BSG Transaction Rulebase . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 535
Adding Rules to the BSG Transaction Rulebase . . . . . . . . . . . . . . . . . . . . . . . . . . 536
Chapter 11
Configuring Junos NAT Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539
Source NAT Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539
Adding a Source NAT Rulebase . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 540
Adding a Rule Set to the Source NAT Rulebase . . . . . . . . . . . . . . . . . . . . . . 540
Adding a Rule to a Source NAT Rule Set . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 541
xxv
Copyright © 2010, Juniper Networks, Inc.
Table of Contents
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Page 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Page 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Page 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Page 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Page 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Page 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Page 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Page 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Page 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Page 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Page 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Page 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Page 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Page 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Page 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Page 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Page 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Page 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Page 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Page 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Page 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Page 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Page 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...