Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Monitor the Service Status of SRX Series Firewalls

You can monitor the service status of the following features on your Juniper Networks® SRX Series Firewall in the Juniper Mist™ cloud portal:

  • Enhanced Web Filtering (EWF)

  • IDP

  • Application Security

You need a valid license for your SRX Series Firewall to use the feature. For more details about license requirements and installation, see Juniper Licensing User Guide.

On the SRX Series Firewall, use the show system license command to display the license name with expiry date.

Check EWF Status

To check Enhanced Web Filtering (EWF) configuration status:

  1. Confirm if EWF is enabled on your SRX Series Firewall in CLI operational mode:

    The Server status: no-config indicates that the EWF is not configured.

  2. Configure EWF on your SRX Series Firewall using the CLI at the [edit] hierarchy level. Use configuration mode and commit the configuration.
    Note:

    We've captured the following configuration from a lab environment and provided it for reference purposes only. Your own configuration may vary based on the specific requirements of your environment.

  3. Check the status in CLI operational mode.

    Now, the status changes to Server status: Juniper Enhanced using Websense server UP. This status indicates that the EWF service is enabled on your device.

  4. You can check the status in the Juniper Mist cloud portal as shown in Figure 1.

Check IDP Status

Before configuring Intrusion Detection and Prevention (IDP) you need to download and install the IDP security package using the following steps:

This example uses the IDP templates which you download and install as follows: .

  1. Download IDP template using the instructions in request security idp security-package download policy-templates command.
  2. Install the templates using the instructions in request security idp security-package install policy-templates command.
  3. Activate the template commit script

    The downloaded templates are saved to the Junos OS configuration database, and they are available in the CLI at the [edit security idp idp-policy] hierarchy level.

  4. Activate the predefined policy as the active policy. In this example, you use Recommended policy as active policy.

    For a list of predefined IDP policy templates, see Predefined IDP Policy Templates.
  5. Enable the IDP policy in your configuration. Following snippet shows a configuration example.Example:
  6. Use the following commands in operational mode to check for the IDP policy status:
    • Recommended IDP policy: show security idp policies:
    • Policy name: show security idp policies
    • IDP status: show security idp status
    • Check the IDP status in Juniper Mist Cloud portal as shown in Figure 1 .

Configure Application Security

On your SRX Series Firewall, Application Security is enabled by default if you have a valid license. The OC-team ensures that all devices have the most up to date application signature version. If you want to change the version or install a custom version, see Predefined Application Signatures for Application Identification.

View Security Service Status in the Juniper Mist Cloud Portal

In the Juniper Mist cloud portal, you can view the status of security services under SECURITY SERVICES panel. Table 1 provides the details of the status.

Table 1: Security Services Status Display
Security Services Display Status Meaning
EWF Enabled Connection to the Websense server is up.
Disabled EWF is not configured on your device.
Down Connection to the Websense server is down.
IDP Enabled IDP is configured and the IDP policy is applied.
Disabled IDP is not configured. In this case, the IDP policy name is displayed blank.
Application Security Enabled Application security is enabled. The application signature version is displayed.
Disabled Application security is not enabled. The application signature version is displayed as zero.

Figure 1 shows security services status in Juniper Mist cloud portal.

Figure 1: Security Services Status Security Services Status
Note:

You can get details such as the presence or absence of a valid license and the status of the security services.