Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Enable Application Visibility on SRX Series Firewalls

The Juniper Networks Application Security (AppSecure) feature is a suite of application-aware security services for the Juniper Networks® SRX Series Firewalls. AppSecure enables you to see the applications on your network and learn how they work. It enables you to observe their behavioral characteristics and assess their relative risk, which allows the Juniper Mist™ cloud to track and report applications passing through the device.

Before You Begin

Consult this list to ensure that you have the licenses and application signatures necessary to enable application visibility.

  • You need a valid AppSecure license on your SRX Series Firewall to use the feature. Use the show system license command to check if your device has the license. For details about license requirements and installation, see Juniper Licensing User Guide.

  • We recommend using the latest version of application signatures. To install the latest version of application signatures, run the following commands on your device:

    1. Download the application signature package version on your device. The command downloads the latest version of the package.

    2. Install the application signature package version on your device.

    3. Verify the application signature package version installed on your device.

    For more details, see Predefined Application Signatures for Application Identification.

    You can see the application signature version in the Juniper Mist cloud portal of your device under the SECURITY SERVICES panel.

    Figure 1: Check Application Security (AppSecure) Version Check Application Security (AppSecure) Version

Enable Application Visibility While Assigning a Device to the Site

Application visibility provides insight into applications running on the network. You can analyze applications running on the network for performance and assurance.

You can enable or disable application visibility on your SRX Series Firewall in the Juniper Mist cloud portal by checking or unchecking the My SRX devices have an App Track License option.

To enable application visibility while assigning a device to a site:

  1. In the Juniper Mist cloud portal, click Organization > Inventory and select WAN Edges from the main menu.
  2. Click the Adopt WAN Edges button.
    Figure 2: WAN Edge Adoption Commands WAN Edge Adoption Commands

    Juniper Mist generates a code snippet in the WAN Edge Adoption window.

  3. Ensure that you've selected the SRX option, and click Copy to Clipboard.
  4. Paste the copied commands to the SRX Series Firewall in configuration mode and commit the configuration. The code creates the following settings on your SRX Series Firewall:
    • Enable SSH.

    • Create a Juniper Mist cloud user.

    • Create a device ID and credentials.

    • Set up the outbound SSH client and associated timers.

    After you commit the configuration on your SRX Series Firewall, the device entry is populated in the inventory page of the Juniper Mist cloud portal.

  5. Select the SRX Series Firewall and select More > Assign to Site.
  6. Select the required site from the available list.
  7. Select one of the options for the application tracking (AppTrack) license.
    Figure 3: Check the AppTrack License Option Check the AppTrack License Option
    • Use site setting for App Track license—Enable application visibility under site setting options.

    • Device has an App Track license—Application visibility is already enabled on the device.

    • Device does NOT have an App Track license—The device does not have application security license.

    If you selected the Use site setting for App Track license option, continue with the following steps:

    1. Navigate to Organization > Site Configurations and select your site.

    2. Scroll down to the WAN Edge Advanced Security pane.

    3. Check or uncheck the box next to My SRX devices have an App Track license

      Figure 4: Check the AppTrack License Option Check the AppTrack License Option
      • Check the box to enable application visibility.
      • Uncheck the box to disable application visibility.
    4. For the Log Source Interface option, provide the IP address of an interface of your SRX Series Firewall. Ensure that the interface has connectivity to the cloud or Internet. This interface acts as the source address for log messages for the application session records.

  8. If you selected either Device has an App Track license or Device does NOT have an App Track license, ensure that the same option is reflected on the Gateways tab in the Application Visibility pane.
    Figure 5: Set the AppTrack License Option Set the AppTrack License Option
You can verify API messages of /sites/site-id/setting to see the following options, depending on whether you selected or unselected My SRX devices have an App Track License:
    • The “gateway_mgmt“: {“app_usage“: True} message indicates that the check box is selected.

    • The “gateway_mgmt“: {“app_usage“: False} message indicates that the check box is not selected.

    Example:

Note:

If you did not select the site settings option, the gateway_mgmt section will not be present in the device API.

Enable Application Visibility on an SRX Series Firewall Already Assigned to a Site

If you did not enable application visibility while assigning the device to a site, you can enable it later.

To enable application visibility on an SRX Series Firewall that you already assigned to a site:

  1. In the Juniper Mist™ cloud portal, select Organization > Site Configurations.
  2. Select the site to which your device is assigned.
  3. Scroll down to the WAN Edge Advanced Security pane.
    Figure 6: Check the AppTrack License Option Check the AppTrack License Option
  4. Check or uncheck the box next to My SRX devices have an App Track license.
    • Check the box to enable application visibility.
    • Uncheck the box to disable application visibility.
  5. For the Log Source Interface option, provide the IP address of an interface on SRX Series Firewall that has connectivity to the cloud or Internet. This interface acts as the source address for log messages for the application session records.
  6. Click Save.
  7. To view the applications details, click Monitor > Service Levels. Select the Insights tab and scroll down to Applications section to get details about applications usage.