- play_arrow Configure
- play_arrow Configure ATP Cloud Features on SRX Series Firewall
- Encrypted Traffic Insights Overview
- Configure Encrypted Traffic Insights
- Adaptive Threat Profiling Overview
- Configure and Deploy Adaptive Threat Profiling
- Adaptive Threat Profiling Use Cases
- Enable DNS Secintel Detection
- DNS DGA Detection Overview
- Enable DNS DGA Detection
- DNS Tunnel Detection Overview
- Enable DNS Tunnel Detection
- DNS Sinkhole Overview
- Configure DNS Sinkhole
- DNS Security Logs
- Geolocation IPs and Juniper Advanced Threat Prevention Cloud
- Configure Juniper Advanced Threat Prevention Cloud With Geolocation IP
- Configure IPFilter Category
- Configure Reverse Shell Detection
- play_arrow Configure AI Predictive Threat Prevention on SRX Series Firewall
-
- play_arrow Configuration Statements and Operational Commands
- play_arrow SRX Series Firewall Commands to Configure Juniper ATP Cloud
-
- play_arrow Use Cases
- play_arrow SecIntel Feeds for MX Series Routers
- play_arrow Amazon Web Services GuardDuty with vSRX Virtual Firewall
- play_arrow Juniper ATP Cloud with Policy Enforcer
-
- play_arrow Troubleshoot
- Juniper Advanced Threat Prevention Cloud Troubleshooting Overview
- Troubleshooting Juniper Advanced Threat Prevention Cloud: Checking DNS and Routing Configurations
- Troubleshooting Juniper Advanced Threat Prevention Cloud: Checking Certificates
- Troubleshooting Juniper Advanced Threat Prevention Cloud: Checking the Routing Engine Status
- Troubleshooting Juniper Advanced Threat Prevention Cloud: Checking the application-identification License
- Viewing Juniper Advanced Threat Prevention Cloud System Log Messages
- Configure traceoptions
- Viewing the traceoptions Log File
- Turning Off traceoptions
- Juniper Advanced Threat Prevention Cloud Dashboard Reports Not Displaying
- Juniper Advanced Threat Prevention Cloud RMA Process
- play_arrow More Documentation
- play_arrow Additional Documentation on Juniper.net
-
Cloud Feeds for Juniper ATP Cloud
The cloud feed URL is set up automatically for you when your SRX Series Firewall is enrolled to the Juniper ATP Cloud. For more information, see Enroll an SRX Series Firewall Using the CLI and Enroll an SRX Series Firewall Using Juniper ATP Cloud Web Portal. There are no further steps you need to do to configure the cloud feed URL.
If you want to check the cloud feed URL on your SRX Series Firewall, run the show
services security-intelligence URL
CLI command. Your output should look
similar to the following:
root@host# show services security-intelligence url https://cloudfeeds.sky.junipersecurity.net/api/manifest.xml
If you do not see a URL listed, run the ops script again as it configures other settings in addition to the cloud feed URL.
Once you configure your SRX Series Firewall, the cloud feeds are automatically sent from Juniper ATP Cloud to the device.
SRX Series Update Intervals for Cloud Feeds
The following table provides the update intervals for each feed type. Note that when the SRX Series Firewall makes requests for new and updated feed content, if there is no new content, no updates are downloaded at that time.
Run the following commands only for troubleshooting purposes:
The
request services security-intelligence uninstall
command uninstalls the SecIntel service from the device.The
request services security-intelligence download
command is used to manually initiate the download of the latest SecIntel updates before the next interval.
Category | Feeds | SRX Series Firewall Update Intervals (in Seconds) |
---|---|---|
Command and Control (C&C) | Juniper Feeds | 1,800 |
Integrated Feeds | 86,400 | |
Customer Feeds | 60 | |
GeoIP | geoip_country | 86,400 |
Allowlist | Juniper Feeds (whitelist_dns) | 1,800 |
Juniper Feeds (whitelist_dns_umbrella) | 86,400 | |
Customer Feeds (domain, IP and Domain Name System (DNS)) | 1,800 | |
Customer Feeds (reverse shell) | 300 | |
Blocklist | Customer Feeds (domain and IP) | 1800 |
Infected Hosts | Infected Hosts | 60 |
Suspicious Hosts | Suspicious Hosts | 60 |
DNS | Juniper Feeds | 1800 |
Customer Feeds | 60 | |
Dynamic Address Group (DAG) | Customer Feeds | 1,800 |
Third party DAG Feeds. For example, Office 365 | 1,800 |