Manually Installing Signatures
Users with the tenant administrator role can install the active signature database on one or more devices, by using the on demand signature installation feature. You can install the signature immediately at a click or schedule the installation for a later time. However, you cannot configure a recurring schedule at which installation must be run, unlike the auto installation feature (see Automating Signature Database Installation). Signatures must be present on the device for application firewall or intrusion prevention system (IPS) features to be used. If you do not install the signature database on a device, the deployment of IPS profiles or application firewall will fail.
Before you install the signature database on the device, ensure that the IPS license is installed on the device. If the IPS license is not installed, only the application signatures will be installed when the signature database installation is triggered.
You can install the signature database on the following devices: NFX150, NFX250, SRX Series, and vSRX Virtual Firewall.
While installing signatures, you can additionally configure settings for installing Intrusion Detection and Prevention (IDP) and enabling micro applications. These settings are applied only to the sites selected.
To install the active signature database:
After the signature database is installed successfully, you can deploy the firewall policy (that references IPS profiles or application signatures) on the device.