Configuring CRLs
After you have obtained a CRL file (.crl) from your CA, use this file to create a Certificate
Revocation object.
In Object Manager, select
CRLs
, then click the icon to display the New CRL dialog box.
Enter a name for the CRL, then click
Load CRL
and load the appropriate .crl file. NSM
uses the information in the .crl file to automatically complete the Issued By and Expire
On fields. Click
OK
to complete the CRL object.
Configuring Extranet Policies
Extranet policies enable you to configure and manage extranet devices (that is, third-party
router).
In this example, you want to update an existing policy on a third-party router to deny
certain ftp traffic from a specific IP address. You can do this by creating a script that
performs the required actions when you update the extranet device. You also need to
create your rule in an Extranet Policy object.
To create an Extranet Policy object:
1.
In the Object Manager, select Extranet Policies. The New ExtranetPolicyObject window
appears.
2.
Enter the name of the Extranet Policy, for example, Extranet Policy1. Add a comment
in the Comments field.
3.
Configure the Extranet Policy object:
•
Click
New
. The New - Rule window appears.
•
Use the up/down arrow to specify an ID for the rule.
•
Add a comment for the rule.
•
Click Deny in the Action field.
•
Select a source address in the Source tab.
•
Select a destination address in the Destination tab.
•
Select
FTP
in the Service tab.
•
Select the integer IDs that you created in the Custom Policy Field object in the
Options tab.
4.
Click
OK
.
When you create the extranet device in NSM, bind the policy to the appropriate interface
and specify the script you want to perform the required update actions. When you update
the device, NSM invokes the script. Any XML output appears in the Job Information
window.
425
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Objects
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Page 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Page 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Page 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Page 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Page 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Page 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Page 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Page 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Page 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Page 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Page 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Page 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Page 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Page 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Page 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Page 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Page 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Page 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Page 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Page 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Page 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Page 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Page 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...