CHAPTER 5
Configuring Security Zones and Policies
for SRX Series
•
Understanding Security Zones and Policies for SRX Series on page 31
•
Example: Configuring Security Zones and Policies for SRX Series on page 32
Understanding Security Zones and Policies for SRX Series
This topic includes the following sections:
•
•
Zones
A zone is a collection of one or more network segments sharing identical security
requirements. To group network segments within a zone, you must assign logical interfaces
from the device to a zone.
Security zones are used to identify traffic flow direction in security policies to control
traffic. On a single device, you can configure multiple security zones and at a minimum,
you must define two security zones, basically to protect one area of the network from
the other.
To configure the security zones, you must:
•
Define zone (security or functional)
•
Add logical interfaces to the zone
•
Define permitted services (example: Telnet, SSH) and protocols (example: OSPF)
destined to device itself.
Default configuration of the branch SRX Series includes two security zones--trust and
untrust. The vlan.0 belongs to the trust zone and ge-0/0/0 belongs to the untrust zone.
For more details on security zones, see
Building Blocks Feature Guide for Security Devices
.
31
Copyright © 2016, Juniper Networks, Inc.
Содержание Junos OS
Страница 6: ...Copyright 2016 Juniper Networks Inc vi Getting Started Guide for Branch SRX Series...
Страница 8: ...Copyright 2016 Juniper Networks Inc viii Getting Started Guide for Branch SRX Series...
Страница 10: ...Copyright 2016 Juniper Networks Inc x Getting Started Guide for Branch SRX Series...
Страница 17: ...PART 1 Overview Introduction to SRX Series Devices on page 3 1 Copyright 2016 Juniper Networks Inc...
Страница 18: ...Copyright 2016 Juniper Networks Inc 2 Getting Started Guide for Branch SRX Series...
Страница 20: ...Copyright 2016 Juniper Networks Inc 4 Getting Started Guide for Branch SRX Series...
Страница 22: ...Copyright 2016 Juniper Networks Inc 6 Getting Started Guide for Branch SRX Series...
Страница 32: ...Copyright 2016 Juniper Networks Inc 16 Getting Started Guide for Branch SRX Series...
Страница 42: ...Copyright 2016 Juniper Networks Inc 26 Getting Started Guide for Branch SRX Series...
Страница 44: ...Copyright 2016 Juniper Networks Inc 28 Getting Started Guide for Branch SRX Series...
Страница 46: ...Copyright 2016 Juniper Networks Inc 30 Getting Started Guide for Branch SRX Series...
Страница 54: ...Copyright 2016 Juniper Networks Inc 38 Getting Started Guide for Branch SRX Series...
Страница 62: ...Copyright 2016 Juniper Networks Inc 46 Getting Started Guide for Branch SRX Series...
Страница 78: ...Copyright 2016 Juniper Networks Inc 62 Getting Started Guide for Branch SRX Series...
Страница 86: ...Copyright 2016 Juniper Networks Inc 70 Getting Started Guide for Branch SRX Series...
Страница 90: ...Copyright 2016 Juniper Networks Inc 74 Getting Started Guide for Branch SRX Series...
Страница 155: ...PART 5 Index Index on page 141 139 Copyright 2016 Juniper Networks Inc...
Страница 156: ...Copyright 2016 Juniper Networks Inc 140 Getting Started Guide for Branch SRX Series...