ON THIS PAGE
Add and Manage DAG Filters
Access the Dynamic Address Group (DAG) Filter page from the menu.
Use a DAG filter to add feeds for the AWS and Azure regions and services that you select. You can configure a maximum of 10 DAG filters for AWS and Azure.
If you do not configure any DAG filter, generic feeds from all AWS and Azure regions and services are displayed. You must configure at least one DAG filter to avoid seeing these generic feeds.
Benefits
You can filter and view the feeds from specific AWS or Azure regions and services relevant to you.
Add DAG Filters
Select .
The DAG Filters page is displayed.
Select either AWS or the Azure tab.
Click the plus icon (
).The Add <AWS or Azure> DAG Filter window is displayed.
(Optional) In the Description field, enter a description for the DAG filter.
Select a region from the Region drop-down list.
When you select a region, the Service drop-down list is available for Azure DAG filter.
Select a service from the Service drop-down list.
When you select the region and service for AWS or Azure, the DAG filter name is automatically generated in the Name field. You cannot edit the DAG filter name.
Note:The exact names for AWS and Azure regions and services are shown in the Name field for the DAG filter. This mapping is relevant only for the manifest file to ensure the DAG feed name is compatible with SRX Series Firewalls.
Junos OS allows a maximum of 32 characters for the DAG filter name. If the feed name is longer than this limit, the cloud feeds manifest file will not display the feed name.
Click OK.
You can see the DAG feeds from the selected region and service in the DAG Filter page.
Table 1: DAG Filters Fields Field Description Name Auto-generated feed name based on selected region and service.
The name includes the selected region and service. For example, if the name of the feed is ap-northeast-2_ROUTE53_RESOLVER, ap-northeast-2 is the region, and ROUTE53_RESOLVER is the service you selected for the feed.
Region Selected AWS or Azure region Feed Name Feed name displayed in the manifest.xml file.
For example: ipfilter_aws_ap-northeast-2_RT53, ipfilter_azure_APAC_Azrrcnfrstrc
Service Selected AWS or Azure service Last Changed Date and time of the most recent feed update Changed By Email of the user who updated the feed Description Description of the AWS or Azure feed Verify the feed name in the manifest.xml file. For example, if the feed name is ipfilter_aws_ap-northeast-2_RT53, it will appear as follows.
<feed data_ts="1753249858" logical_domain="root-logical-system" name="ipfilter_aws_ap-northeast-2_RT53" objects="25" options="" ttl="157680000" types="ip_addr ip_range ip_subnet ipv6_addr ipv6_range" update_interval="1800" version="20230707.1" vrf="junos-default-vrf"> <data>
Run the CLI command
set security dynamic-address address-name amazonaws profile category IPFilter feed <feed-name-in-manifest-file>on SRX Series Firewalls to add AWS feeds,set security dynamic-address address-name amazonaws profile category IPFilter feed ipfilter_aws_ap-northeast-2_RT53
Run the CLI command
set security dynamic-address address-name microsoftazure profile category IPFilter feed <feed-name-in-manifest-file>on SRX Series Firewalls to add Azure feeds.set security dynamic-address address-name microsoftazure profile category IPFilter feed ipfilter_azure_APAC_Azrrcnfrstrc
Run the CLI command
show security dynamic-address category-name IPFilter feed-name <feed name in manifest file>on SRX Series Firewalls to view the added feeds.show security dynamic-address category-name IPFilter feed-name ipfilter_aws_ap-northeast-2_RT53 No. IP-start IP-end Feed Address CountryCode 1 10.34.89.64 10.34.89.127 IPFilter/ipfilter_aws_ap-northeast-2_RT53 amazonaws -- 2 10.36.3.96 10.36.3.127 IPFilter/ipfilter_aws_ap-northeast-2_RT53 amazonaws -- 3 10.36.3.160 10.36.3.175 IPFilter/ipfilter_aws_ap-northeast-2_RT53 amazonaws -- 4 10.36.3.192 10.36.3.223 IPFilter/ipfilter_aws_ap-northeast-2_RT53 amazonaws -- 5 10.36.3.224 10.36.3.255 IPFilter/ipfilter_aws_ap-northeast-2_RT53 amazonaws --
show security dynamic-address category-name IPFilter feed-name ipfilter_azure_APAC_Azrrcnfrstrc No. IP-start IP-end Feed Address CountryCode 1 10.145.72.0 10.145.72.7 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 2 10.145.72.8 10.145.72.9 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 3 10.190.132.42 10.190.132.43 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 4 10.190.132.184 10.190.132.191 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 5 10.200.250.192 10.200.250.193 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 6 10.240.144.50 10.240.144.51 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 7 10.240.144.80 10.240.144.87 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 8 10.243.24.48 10.243.24.55 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure -- 9 10.243.24.56 10.243.24.57 IPFilter/ipfilter_azure_APAC_Azrrcnfrstrc microsoftazure --
Manage DAG Filter
-
Edit—Select the DAG filter, and then click the pencil icon (
).
-
Delete—Select the DAG filter, and then click the trash can icon (
).