Resetting the SRX Series Device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Resetting the Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Resetting Your Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Resetting Your SRX Series to a Rescue Configuration . . . . . . . . . . . . . . . 27
Resetting Your SRX Series to Factory Settings . . . . . . . . . . . . . . . . . . . . . 27
Configuring Basic SRX Series Features
Configuring Security Zones and Policies for SRX Series . . . . . . . . . . . . . . . . . 31
Understanding Security Zones and Policies for SRX Series . . . . . . . . . . . . . . . . . . 31
Zones . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31
Security Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Example: Configuring Security Zones and Policies for SRX Series . . . . . . . . . . . . . 32
Configuring NAT for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
Understanding NAT for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
Example: Configuring Destination NAT for SRX Series . . . . . . . . . . . . . . . . . . . . . 40
Managing Licenses for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Updating Licenses for a Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Configuring UTM for Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
Understanding Unified Threat Management for Branch SRX Series . . . . . . . . . . . 49
Example: Configuring Unified Threat Management for a Branch SRX Series . . . . . 51
Default UTM Policy for Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
Default UTM Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
Predefined UTM Profile Configuration for Branch SRX Series . . . . . . . . . . . . . . . . 54
Antispam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
Antivirus . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
Web Filtering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
Configuring Intrusion Detection and Prevention for SRX Series . . . . . . . . . 63
Understanding Intrusion Detection and Prevention for SRX Series . . . . . . . . . . . . 63
Example: Configuring Intrusion Detection and Prevention for SRX Series . . . . . . 64
Understanding Stateful Firewall, IPsec VPN, and Chassis Cluster for
Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71
Understanding Branch SRX Series Stateful Firewall Functionality . . . . . . . . . . . . . 71
Understanding IPsec VPN for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
Understanding Chassis Cluster for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
Configuration Statements and Operational Commands
Configuration Statements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
Security Configuration Statement Hierarchy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
[edit security address-book] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
[edit security idp] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77
[edit security ike] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87
[edit security ipsec] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88
[edit security nat] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90
[edit security policies] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93
Copyright © 2016, Juniper Networks, Inc.
iv
Getting Started Guide for Branch SRX Series
Содержание Junos OS
Страница 6: ...Copyright 2016 Juniper Networks Inc vi Getting Started Guide for Branch SRX Series...
Страница 8: ...Copyright 2016 Juniper Networks Inc viii Getting Started Guide for Branch SRX Series...
Страница 10: ...Copyright 2016 Juniper Networks Inc x Getting Started Guide for Branch SRX Series...
Страница 17: ...PART 1 Overview Introduction to SRX Series Devices on page 3 1 Copyright 2016 Juniper Networks Inc...
Страница 18: ...Copyright 2016 Juniper Networks Inc 2 Getting Started Guide for Branch SRX Series...
Страница 20: ...Copyright 2016 Juniper Networks Inc 4 Getting Started Guide for Branch SRX Series...
Страница 22: ...Copyright 2016 Juniper Networks Inc 6 Getting Started Guide for Branch SRX Series...
Страница 32: ...Copyright 2016 Juniper Networks Inc 16 Getting Started Guide for Branch SRX Series...
Страница 42: ...Copyright 2016 Juniper Networks Inc 26 Getting Started Guide for Branch SRX Series...
Страница 44: ...Copyright 2016 Juniper Networks Inc 28 Getting Started Guide for Branch SRX Series...
Страница 46: ...Copyright 2016 Juniper Networks Inc 30 Getting Started Guide for Branch SRX Series...
Страница 54: ...Copyright 2016 Juniper Networks Inc 38 Getting Started Guide for Branch SRX Series...
Страница 62: ...Copyright 2016 Juniper Networks Inc 46 Getting Started Guide for Branch SRX Series...
Страница 78: ...Copyright 2016 Juniper Networks Inc 62 Getting Started Guide for Branch SRX Series...
Страница 86: ...Copyright 2016 Juniper Networks Inc 70 Getting Started Guide for Branch SRX Series...
Страница 90: ...Copyright 2016 Juniper Networks Inc 74 Getting Started Guide for Branch SRX Series...
Страница 155: ...PART 5 Index Index on page 141 139 Copyright 2016 Juniper Networks Inc...
Страница 156: ...Copyright 2016 Juniper Networks Inc 140 Getting Started Guide for Branch SRX Series...