changeable firmware that runs on IDP Sensors, optional security modules for the ISG
Series Integrated Security Gateways and IDP-capable devices.
The following sections explain how to manage the attack object database:
•
Updating the Attack Object Database on page 290
•
Verifying the Attack Object Database Version on page 293
•
Updating the IDP Detector Engine on page 295
•
Example: Confirm IDP Engine Version on page 296
•
Scheduling Security Updates on page 296
Updating the Attack Object Database
You can update the attack object database for managed devices that have deep
inspection or IDP capabilities.
•
For devices running ScreenOS version 5.0.0-IDP1, ScreenOS 5.1 and later, or standalone
IDP, or supported versions of Junos, you must download new attack objects from the
attack object database server to the GUI Server, and then download the new objects
to your managed devices. IDP attack objects are loaded automatically when an IDP
rulebase is loaded; DI attack objects must be loaded manually.
•
For devices running ScreenOS version 5.0, you must configure the devices to contact
the attack object database server, and then prompt the devices to download new
attack objects from the server.
To update a managed device with new DI attack objects, you must first obtain a DI
subscription for your device. For details, see “Activating Subscription Services” on page 289.
Updating Attack Objects for IDP-Enabled devices
You can update attack objects by downloading new attack objects and a new detector
engine from the attack object database server to the GUI Server, then downloading the
new objects to your managed devices.
You can perform a network update if the NSM GUI Server has an Internet connection,
either directly or through a proxy. During a network update, the GUI Server contacts the
Attack Object Database server (managed by Juniper Networks) and automatically
downloads the necessary attack object files.
You can perform a local update if the GUI Server does not have Internet connectivity or
you do not want to perform a network update. To prepare for a local update, you manually
download the attack objects files from the Attack Object Database server (managed by
Juniper Networks), then copy these files to a local directory on the GUI Server. Then,
during the local update, you specify the path to these files.
Preparing for a Local Update
Complete the following steps before you perform a local update:
Copyright © 2010, Juniper Networks, Inc.
290
Network and Security Manager Administration Guide
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Page 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Page 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Page 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Page 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Page 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Page 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Page 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Page 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Page 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Page 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Page 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Page 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Page 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Page 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Page 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Page 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Page 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Page 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Page 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Page 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Page 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Page 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Page 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...