The following steps explain configuring VMWare NSX with Policy Enforcer:
Figure 59: Adding NSX Manager Page
Secure Fabric
Policy Enforcement Group (PEG)
Sky ATP Realm
Threat policies for the following threat types:
Command and Control (C&C) Server
Infected Hosts
Malware
The Threat Prevention Policy Setup page appears.
The Threat Prevention Policy Setup page appears, as shown in Figure 60. Some of the resources are already configured as you discover the NSX Manager.
Figure 60: Guided Setup Page
To create a secure fabric site in Policy Enforcer for NSX based environment, you require two parts : NSX Manager and edge firewall. In the Add Enforcement Points page, add vSRX, as shown in the topology, as a edge firewall. Select the vSRX device listed under the Available column and move it to the Selected column. You now have two enforcement points within the Secure Fabric.
Click Next.
Click. Next.
If the Sky ATP realm is already created, click Assign Sites in the Sites Assigned column and chose the Secure Fabric site. The Sky ATP realm and Secure Fabric are now associated.
Click. Next.
Click Assign groups in the Policy Enforcement Group column to associate the policy enforcement group with the policy.
Security Director takes the snapshot of the firewall by performing the rule analysis and threat remediation rules are pushed into the edge firewall.
Click Finish.
Note: The GeoIP feeds are not used with the NSX Connectors.
© 2018 Juniper Networks, Inc. All rights reserved