- play_arrow Juniper Web Device Manager
- play_arrow Getting Started
-
- play_arrow Add SRX Series Firewall to Security Director Cloud
- play_arrow Dashboard
- play_arrow J-Web Dashboard
-
- play_arrow Monitor
- play_arrow Network
- play_arrow Logs
- play_arrow Maps and Charts
- play_arrow Statistics
- play_arrow Reports
-
- play_arrow Device Administration
- play_arrow Basic Settings
- play_arrow Cluster Management
- play_arrow User & Roles
- play_arrow Multi Tenancy—Resource Profiles
- play_arrow Multi Tenancy—Interconnect Ports
- play_arrow Multi Tenancy—Logical Systems
- play_arrow Multi Tenancy—Tenants
- play_arrow Certificate Management—Device Certificates
- play_arrow Certificate Management—Trusted Certificate Authority
- About the Trusted Certificate Authority Page
- Generate Default Trusted Certificate Authorities
- Enroll a CA Certificate
- Import a CA Certificate
- Add a Certificate Authority Profile
- Edit a Certificate Authority Profile
- Delete a Certificate Authority Profile
- Search Text in the Trusted Certificate Authority Table
- play_arrow Certificate Management—Certificate Authority Group
- play_arrow License Management
- play_arrow Security Package Management
- play_arrow ATP Management
- play_arrow Operations
- play_arrow Software Management
- play_arrow Configuration Management
- play_arrow Alarm Management
- play_arrow RPM
- play_arrow Tools
- play_arrow Reset Configuration
-
- play_arrow Network
- play_arrow Connectivity—Interfaces
- play_arrow Connectivity—VLAN
- play_arrow Connectivity—Link Aggregation
- play_arrow Connectivity—Wireless LAN
- play_arrow DHCP Client
- play_arrow DHCP Server
- play_arrow Firewall Filters—IPv4
- play_arrow Firewall Filters—IPv6
- play_arrow Firewall Filters—Assign to Interfaces
- play_arrow NAT Policies
- play_arrow NAT Pools
- play_arrow Destination NAT
- play_arrow Static NAT
- play_arrow NAT Proxy ARP/ND
- play_arrow Static Routing
- play_arrow RIP Routing
- play_arrow OSPF Routing
- play_arrow BGP Routing
- play_arrow Routing Instances
- play_arrow Routing—Policies
- play_arrow Routing—Forwarding Mode
- play_arrow CoS—Value Aliases
- play_arrow CoS—Forwarding Classes
- play_arrow CoS Classifiers
- play_arrow CoS—Rewrite Rules
- play_arrow CoS—Schedulers
- play_arrow CoS—Scheduler Maps
- play_arrow CoS—Drop Profile
- play_arrow CoS—Virtual Channel Groups
- play_arrow CoS—Assign To Interface
- play_arrow Application QoS
- play_arrow IPsec VPN
- play_arrow Manual Key VPN
- play_arrow Dynamic VPN
-
- play_arrow Security Policies and Objects
- play_arrow Security Policies
- play_arrow Metadata Streaming Policy
- play_arrow Zones/Screens
- play_arrow Zone Addresses
- play_arrow Global Addresses
- play_arrow Services
- play_arrow Dynamic Applications
- play_arrow Application Tracking
- play_arrow Schedules
- play_arrow Proxy Profiles
-
ON THIS PAGE
About the SecIntel Profiles Page
You are here: Security Services > Advanced Threat Prevention > SecIntel Profiles.
Juniper Networks Security Intelligence (SecIntel) provides carefully curated and verified threat intelligence from industry-leading threat feeds to SRX Series Firewalls. This enables blocking malicious and unwanted traffic such as Command and Control (C&C) communications, GeoIP, Attacker IPs, and more with minimum latency. SecIntel delivers real-time threat intelligence by enabling automatic and responsive traffic filtering.
Configure SecIntel profiles to work with security intelligence feeds, such as C&C, DNS, and infected hosts. The Security Intelligence process is responsible for downloading the security intelligence feeds and parsing from the feed connector or ATP Cloud feed server. Anything that matches these scores is considered malware or an infected host.
Tasks You Can Perform
You can perform the following tasks from this page:
View the list of C&C, DNS, and infected hosts profiles. To do this, select All, Command & Control, DNS, or Infected Hosts from the View by list.
Configure DNS sinkhole. See Configure DNS Sinkhole.
Create a C&C profile. See Create a Command and Control Profile.
Edit a C&C profile. See Edit a Command and Control Profile.
Delete a C&C profile. See Delete a Command and Control Profile.
Create a DNS profile. See Create a DNS Profile.
Edit a DNS profile. See Edit a DNS Profile.
Delete a DNS profile. See Delete a DNS Profile.
Create an infected hosts profile. See Create an Infected Hosts Profile.
Edit an infected hosts profile. See Edit an Infected Hosts Profile.
Delete an infected hosts profile. See Delete an Infected Hosts Profile.
Clone a C&C, DNS, or an infected hosts profile. To do this:
Select an existing C&C, DNS, or an infected hosts profile to clone from the SecIntel Profiles page.
Select Clone from the More link.
The Clone <Command & Control, DNS, or Infected Hosts> Profile page opens with editable fields.
Show or hide columns in the SecIntel Profiles table. To do this, use the Show Hide Columns icon in the upper-right corner of the page, and select the options to show or deselect to hide options on the page.
Advanced search for SecIntel profiles. To do this, use the search text box present above the table grid. The search includes the logical operators as part of the filter string. In the search text box, when you hover over the icon, it displays an example filter condition. When you start entering the search string, the icon indicates whether the filter string is valid or not.
For an advanced search:
Enter the search string in the text box.
Based on your input, a list of items from the filter context menu appears.
Select a value from the list and then select a valid operator to perform the advanced search operation.
Note:Press Spacebar to add an AND operator or an OR operator to the search string. Press backspace at any point of time while entering a search criteria, only one character is deleted.
Press Enter to display the search results in the grid.
Field Descriptions
Table 1 describes the fields on the SecIntel Profiles page.
Field | Description |
---|---|
Name | Displays the SecIntel profile name. |
Type | Displays if the SecIntel profile is a C&C, a DNS, or an infected hosts profile. |
Feeds | Displays the feeds that are associated with the C&C, DNS, or infected hosts profile. |
Block Action | Displays the notification action taken with the block action. For example, Redirect URL, Redirect Message, and Sinkhole. |
Description | Displays the description of the SecIntel profile. |