Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Announcement: Try the Ask AI chatbot for answers to your technical questions about Juniper products and solutions.

close
header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Juniper Security Director Cloud User Guide
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Create and Manage Exempt Rules

date_range 26-Feb-25

You can create intrusion prevention system (IPS) exempt rules only for customized IPS profiles.

To create an exempt rule:

  1. Select Secure Edge > Security Subscriptions > IPS.

    The IPS Policy page opens.

  2. Click the Exempt Rules tab.
  3. Click the add (+) icon.

    The parameters for an exempt rule are displayed inline at the top of the page.

  4. Complete the configuration according to the guidelines in Table 1.
  5. Click the check mark () to save your changes.

    The changes are saved and a confirmation message is displayed at the top of the page.

    You can use the IPS profile in a firewall policy intent. When you deploy the firewall policy on the device, the IPS and exempt rules associated with the profile are also deployed.

    Table 1: Create Exempt Rule Settings

    Setting

    Guideline

    Name

    Juniper Secure Edge generates a unique rule name by default. You can modify the name.

    The name must begin with an alphanumeric character and can contain maximum 63 characters, which includes alphanumeric characters and some special characters, such as colons, hyphens, forward slashes, periods, and underscores.

    Description

    Enter a description containing maximum 1024 characters for the rule.

    IPS Signatures

    Add one or more IPS signatures and IPS signature static and dynamic groups to be associated with the rule:

    1. Click inside the text box with the + icon.

      A list of IPS signatures and IPS signature static and dynamic groups opens.

    2. (Optional) Click the add (+) icon to add signatures. The Add IPS Signatures popup window opens.

    3. (Optional) Enter a search term and press Enter to filter the list of items displayed.

    4. Click a list item to add it to the IPS signatures and IPS signature static or dynamic groups associated with the rule.

    5. (Optional) Repeat the preceding step to add more signatures, static groups, and dynamic groups.

Manage Exempt Rules
  • Edit—Select the rule, and then click . You can edit exempt rules associated only with customized IPS profiles, and not the rules associated with predefined (system-generated) profiles. If the exempt rule belongs to an IPS profile that is referenced in a firewall policy intent, then the firewall policy is marked for deployment. You must deploy the firewall policy for the changes to take effect on the device.

  • Clone—Select the rule, and then click More > Clone. You can clone exempt rules associated only with customized IPS profiles, and not rules associated with predefined (system-generated) profiles.

  • Delete—Select the rule, and then click . You can delete exempt rules associated only with customized IPS profiles, and not the rules associated with predefined (system-generated) profiles. If the deleted exempt rule belongs to an IPS profile that is referenced in a firewall policy intent, then the firewall policy is marked for deployment. You must deploy the firewall policy for the changes to take effect on the device.

footer-navigation