Add Juniper devices

Relevant for: AFA Administrators

This topic describes how to add Juniper devices to AFA.

Tip: If you have multiple Juniper Netscreen or SRX devices, we recommend adding the Juniper NSM or Space that manages these devices.

This automatically enables AFA to analyze any devices managed by the NSM or Space device.

Juniper NSM devices in AFA

The following sections describe how Juniper NSM devices are added to AFA:

Consider the following when adding NSM devices:

Juniper NSM 2007 managing Netscreen devices

If you have a Juniper NSM 2007 managing Netscreen devices, you must add each Netscreen device separately, and specify that the Netscreen device logs are collected from the NSM.

For more details, see Juniper Netscreen devices in AFA.

NAT support for SRX devices

NAT is not supported for Juniper SRX devices defined in AFA under an NSM. If you need NAT support, add your Juniper SRX device separately.

For details, see Juniper SRX devices in AFA.

Device permissions

AFA requires the following to collect data from NSM devices:

Add a Juniper NSM device

This procedure describes how to add a Juniper NSM to AFA. AFA uses the NSM API 2008, available in NSM versions 2008 and higher, to connect to the NSM and collect data.

Do the following:

  1. Set your NSM device to listen to port 8443 on the IP address of its interface.

  2. If you are using a Juniper NSM 2007 or 2008, enable AFA to translate rule numbers to rule IDs.

    These rule IDs are available by default in NSM 2009 traffic logs.

  3. Access the Devices Setup page. For more details, see Access the DEVICES SETUP page.

  4. In the vendor and device selection page, select Juniper > NSM (NSM 2008 or above).

  5. Complete the following fields as needed.

  6. Click Next to continue to the Juniper NSM Step 2/2 page.

    This page lists the devices that are managed by the NSM, including standalone devices and virtual systems.

    Do the following:

    Add Device column

    Select the checkbox for any devices you want to define via the NSM.

    Log Analysis column

    Select one of the following to determine log functionality for a selected device:

    • None to disable logging.
    • Standard to enable logging.
    • Extensive to enable logging and the Intelligent Policy Tuner.

    This enables AFA to detect policy optimization data, such as unused rules, and display them in the Policy Optimization section of the AFA report. For details, see POLICY OPTIMIZATION page.

    Migrate from currently defined Netscreen column

    Displayed if you have Netscreen devices managed by this NSM already defined in AFA.

    Select devices to migrate for AFA to delete them in the background and add them back via the NSM.

    Note: Juniper SRX devices already defined in AFA cannot be migrated. To define the device as managed by the NSM, first delete the SRX device from AFA, and then redefine via the NSM.

  7. Complete the remaining fields as needed, and click Finish.

    The new device is added to the device tree.

  8. If you selected Set user permissions, the Edit users dialog box appears.

    In the list of users displayed, select one or more users to provide access to reports for this account.

    To select multiple users, press the CTRL button while selecting.

    Click OK to close the dialog.

A success message appears to confirm that the device is added.

Back to top

Junos Space Security Director devices in AFA

The following sections describe how ASMS connects to Junos Space Security Director devices:

Consider the following when adding Junos Space Security Director devices to AFA:

Network connectivity

The following diagram shows an ASMS Central Manager or Remote Agent connecting to a Juniper SPACE device.

Device permissions

ASMS requires the following for the user used to access your Juniper SPACE devices:

Add a Junos Space Security Director device

This procedure describes how to add a Junos Space Security Director device to AFA. Once added, all SRX devices managed by the Space device are also added to AFA, as well as any Virtual Routers or Secure Wires managed by the SRX device or LSYS.

For more details, see Virtual Router, VRF, and Secure Wire support.

Do the following:

  1. Access the Devices Setup page. For details, see Access the DEVICES SETUP page.

  2. In the vendor and device selection page, click Juniper > Junos Space Security Director.

  3. Complete the fields as needed.

  4. If you enabled ActiveChange, the ActiveChange License Agreement dialog box appears.

    Select I Agree and click OK.

  5. Click Next to continue to the Junos Space Security Director - Step 2/2 page.

    This page lists the devices that are managed by the Juniper Space, including standalone devices and logical systems.

    Do the following:

    Add Device column

    Select the checkbox for any devices you want to define via the Space device.

    Log Analysis column

    Select one of the following to determine log functionality for a selected device:

    • None to disable logging.
    • Standard to enable logging.
    • Extensive to enable logging and the Intelligent Policy Tuner.

    This enables AFA to detect policy optimization data, such as unused rules, and display them in the Policy Optimization section of the AFA report. For details, see POLICY OPTIMIZATION page.

  6. Select the remaining options as needed:

    Real-time change monitoring

    Select this option to enable real-time alerting upon configuration changes. For details, see Configure real-time monitoring.

    Set user permissions

    Select this option to set user permissions for this device.

  7. Click Finish.

    The new Space device is added to the device tree, showing each individual device, LSYS, or routing instance configured.

    Space devices and the devices they manage appear in the device tree with a potentially four-tier hierarchy. For example: Juniper Space Security Director (Management Device) > SRX > LSYS > Virtual Router, VRF, or Secure Wire

    For more details, see Virtual Router, VRF, and Secure Wire support.

    Note: SRX clusters in passive/active mode appear as a single node in the tree, while SRX clusters in active/active mode appear as two nodes.

    Empty routers or LSYSs, unsupported routing instances, or LSYSs that contain only unsupported routing instances, are not added to the device tree.

  8. If you selected Set user permissions, the Edit users dialog box appears.

    In the list of users displayed, select one or more users to provide access to reports for this account.

    To select multiple users, press the CTRL button while selecting.

    Click OK to close the dialog.

A success message appears to confirm that the device is added.

Back to top

Juniper Netscreen devices in AFA

The following sections describe how ASMS connects to Juniper Netscreen devices:

Network connectivity

The following diagram shows an ASMS Central Manager or Remote Agent connecting to a Juniper Netscreen device.

Device requirements

ASMS requires the following to connect to Juniper Netscreen devices:

Add a Juniper Netscreen to AFA

This procedure describes how to add a Juniper Netscreen to AFA.

Do the following:

  1. Access the Devices Setup page. For details, see Access the DEVICES SETUP page.

  2. In the vendor and device selection page, select Juniper > Netscreen.

  3. Complete the fields as needed:

  4. Click Finish. The new device is added to the device tree.

  5. If you selected Set user permissions, the Edit users dialog box appears.

    In the list of users displayed, select one or more users to provide access to reports for this account.

    To select multiple users, press the CTRL button while selecting.

    Click OK to close the dialog.

Back to top

Juniper SRX devices in AFA

The following sections describe how ASMS connects to Juniper SRX devices:

Network connection

The following diagram shows an ASMS Central Manager or Remote Agent connecting to a Juniper SRX device.

Device permissions

ASMS requires the following permissions for your Juniper SRX routers:

Add a Juniper SRX device to AFA

This procedure describes how to add a Juniper SRX to AFA.

Do the following:

  1. Access the Devices Setup page. For details, see Access the DEVICES SETUP page.
  2. In the vendor and device selection page, select Juniper > SRX.
  3. Complete the fields as needed.

  4. If you enabled ActiveChange, the ActiveChange License Agreement dialog box appears.

    Select I Agree and click OK.

  5. Click Finish.
  6. If you selected Set user permissions, the Edit users dialog box appears.

    In the list of users displayed, select one or more users to provide access to reports for this account.

    To select multiple users, press the CTRL button while selecting.

    Click OK to close the dialog.

The new device is added to the device tree, and a success message appears to confirm that the device is added.

Configure Juniper SRX devices to send traffic logs

ASMS can collect log data by receiving traffic logs from the device itself, or by collecting syslog messages from an external, remote syslog-ng server.

Configure this as needed. For details, see the Juniper Knowledge Base.

Back to top

Juniper routers in AFA

The following sections describe how ASMS connects to Juniper JUNOS routers:

Note: Juniper routing devices with large route tables may cause data collection to take longer than usual.

For details about specific routers supported, see the AlgoSec Support Matrix.

Network connectivity

The following diagram shows an ASMS Central Manager or Remote Agent connecting to a Juniper router.

Device requirements

ASMS connects to Juniper routing devices using SSH, and requires a super-user with the following permissions:

  • show version
  • show route active-path all
  • show configuration

Note: If you need to use a user that is not a super-user, contact AlgoSec support.

Add a Juniper router to AFA

This procedure describes how to add a Juniper router to AFA.

Do the following:

  1. Access the Devices Setup page. For details, see Access the DEVICES SETUP page.
  2. In the vendor and device selection page, select Juniper > M/E Routers.
  3. Complete the fields as needed.

  4. Click Finish. The new device is added to the device tree.
  5. If you selected Set user permissions, the Edit users dialog box appears.

    In the list of users displayed, select one or more users to provide access to reports for this account.

    To select multiple users, press the CTRL button while selecting.

    Click OK to close the dialog.

A success message appears to confirm that the device is added.

Back to top

Configure Juniper STRM to forward logs to a Syslog-ng server

This procedure describes how to configure Juniper STRM to forward logs to a syslog-ng server.

Do the following:

  1. Log in to the STRM Log Manager interface, and click the Admin tab.
  2. On the left, click Data Sources > Syslog Forwarding Destinations > Add.
  3. Enter the syslog-ng server's IP address and port, and click Save.

All logs that are sent to the Juniper STRM device will be forwarded to the syslog-ng server.

Back to top