Configure Networks for SRX Series Firewalls
Networks are sources of the request in your Juniper WAN Assurance design. On the Juniper® SRX Series Firewall, networks create Address books used as the source for Security Policies and Advanced Policy Based Routing (APBR) Policies.
Networks enable you to define groups of users. In a WAN design, you need to identify the sources accessing your applications over the LAN segment and set up the users. Users are source addresses, which you can use later in the application policies.
Once you have created networks in the Juniper Mist™ cloud portal, you can use networks across the entire organization in the portal. WAN Assurance design uses networks as the source in the application policy.
To configure networks:
Site Variables
You can configure the site variables on a per-site basis. Site variables allow you to use the same network definition with different values for each site without having to define multiple networks. Variables have the format {{variable_name}}. Defining networks with variables is common practice in WAN edge template configuration.
The fields with this label also display the matching variables (if configured) as you start typing a specific variable in it. This field lists variables from all sites within the organization.
The organization-wide list of variables can be viewed using GET /api/v1/orgs/:org_id/vars/search?var=*. This list is populated as variables are added under site settings.
Figure 2 shows two samples of configuring a network using absolute values and site variables.
You can define the site variables in the Organization > Admin> Site Configuration pane.
This task uses variables for the VLAN ID and subnet IP address. Site variables that contain the first three octets substitute the subnet IP address variable values as shown in Figure 4.