Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

コマンドを使用してクラウド Juniper Security Director へのブラウンフィールドSRXシリーズファイアウォールのオンボーディング

このトピックでは、CLIコマンドを使用して、既存のサービス中のSRXシリーズファイアウォールを Juniper Security Director Cloud にオンボーディングする簡単な手順を説明します。

始める前に

  • ファイアウォールSRXシリーズそれぞれのポートで Juniper Security Director Cloud 完全修飾ドメイン名(FQDN)と通信できることを確認します。ホームリージョンごとにFQDNは異なります。FQDNマッピングの詳細については、以下の表を参照してください。

    表1:リージョンからFQDNへのマッピング
    地域 目的 ポート IPv4/IPv6 の FQDN

    北バージニア州

    ZTP

    443

    IPv4:srx.sdcloud.juniperclouds.net

    IPv6:srx-v6.sdcloud.juniperclouds.net

    アウトバウンドSSH

    7804

    IPv4:srx.sdcloud.juniperclouds.net

    IPv6:srx-v6.sdcloud.juniperclouds.net

    Syslog TLS

    6514

    IPv4:srx.sdcloud.juniperclouds.net

    IPv6:srx-v6.sdcloud.juniperclouds.net

    オハイオ州

    ZTP

    443

    IPv4:srx.jsec2-ohio.juniperclouds.net

    IPv6:srx-v6.jsec2-ohio.juniperclouds.net

    アウトバウンドSSH

    7804

    IPv4:srx.jsec2-ohio.juniperclouds.net

    IPv6:srx-v6.jsec2-ohio.juniperclouds.net

    Syslog TLS

    6514

    IPv4:srx.jsec2-ohio.juniperclouds.net

    IPv6:srx-v6.jsec2-ohio.juniperclouds.net

    カナダ、モントリオール

    ZTP

    443

    IPv4:srx.jsec-montreal2.juniperclouds.net

    IPv6:srx-v6.jsec-montreal2.juniperclouds.net

    アウトバウンドSSH

    7804

    IPv4:srx.jsec-montreal2.juniperclouds.net

    IPv6:srx-v6.jsec-montreal2.juniperclouds.net

    Syslog TLS

    6514

    IPv4:srx.jsec-montreal2.juniperclouds.net

    IPv6:srx-v6.jsec-montreal2.juniperclouds.net

    フランクフルト、ドイツ

    ZTP

    443

    IPv4:srx.jsec-frankfurt.juniperclouds.net

    IPv6:srx-v6.jsec-frankfurt.juniperclouds.net

    アウトバウンドSSH

    7804

    IPv4:srx.jsec-frankfurt.juniperclouds.net

    IPv6:srx-v6.jsec-frankfurt.juniperclouds.net

    Syslog TLS

    6514

    IPv4:srx.jsec-frankfurt.juniperclouds.net

    IPv6:srx-v6.jsec-frankfurt.juniperclouds.net

  • TCPポート53とUDPポート53を使用して、Google DNSサーバー(IPアドレス - 8.8.8.8および8.8.4.4)に接続します。Google DNSサーバーは、SRXシリーズファイアウォールの工場出荷時設定でデフォルトサーバーとして指定されています。ZTPを使用してファイアウォールをオンボーディングする際には、これらのデフォルトDNSサーバーを使用する必要があります。他の方法を使用してファイアウォールをオンボーディングする場合でも、プライベートDNSサーバーを使用できます。プライベートDNSサーバーが Juniper Security Directorクラウド FQDNを解決できることを確認する必要があります。

ワークフロー

図1:ブラウンフィールド導入Flowchart titled Brownfield Onboarding outlining steps for onboarding SRX Series Firewall with Juniper Security Director Cloud: Ensure communication with Juniper Security Director Cloud, decide on subscriptions, create account and add subscriptions, add in-service SRX Series Firewall using commands, associate firewall with Juniper Security Director Cloud, start managing SRX Series Firewalls.におけるクラウドJuniper Security DirectorへのSRXシリーズファイアウォールのオンボーディング

また、以下の方法を使用して、既存のサービス中(ブラウンフィールド)SRXシリーズファイアウォールをオンボーディングすることもできます。

SRXシリーズファイアウォールをJuniper Security Director Cloudにオンボーディングします

  1. 必要な Juniper Security Director Cloudサブスクリプション を決定します。サブスクリプションのご購入については、営業担当者またはアカウントマネージャーにお問い合わせください。ポータルでデフォルトで利用可能な 30 日間のトライアル サブスクリプションを使用することもできます。
  2. https://sdcloud.juniperclouds.net/ に移動し、組織アカウントを作成をクリックします。

    画面の指示に従ってアカウントをアクティブ化します。アカウントアクティベーションリクエストが承認されるまでに最大7営業日かかります。

  3. Juniper Security Director Cloudポータルにログインし、サブスクリプションを追加をクリックし、詳細を入力してOKをクリックしますJuniper Security Director Cloud interface showing Add Subscriptions pop-up in Subscriptions section under Administration menu with navigation options on the left.

    追加したサブスクリプションを 管理 > サブスクリプションから表示します。サブスクリプションが表示されない場合は、 管理 > ジョブ ページに移動してステータスを確認してください。

  4. Juniper Security Director Cloudに移動し、デバイスのインベントリ>を選択します。+アイコンをクリックしてデバイスを追加します。
  5. SRXデバイスを導入をクリックし、以下のいずれかを選択します。
    • SRXデバイス

    • SRXクラスター

    • SRXマルチノード高可用性(MNHA)ペア

    • User interface for adding Juniper SRX devices: options to adopt devices or register for Zero Touch Provisioning. Includes device type selection and Junos OS support notice.画面
    の指示に従って続行します。
  6. デバイスページからコマンドをコピーアンドペーストして、SRXシリーズファイアウォールに貼り付けます。プライマリクラスターデバイスコンソール、またはMNHAペア内の各デバイスのコマンドを貼り付けます。変更をコミットします。Screenshot of Juniper Security Director Cloud Devices section highlighting Adopt Device option with red notification instructions.

    デバイスの検出には数秒かかります。デバイス検出が成功したら、 デバイス ページで以下のフィールドを確認します。

    • 管理ステータスが「検出中」から「アップ」に変わります。

    • インベントリステータスデバイス構成ステータス が「 同期外 」から 「同期中」に変わります。

      検出に失敗した場合は、 管理 > ジョブ ページに移動してステータスを表示します。

      デバイスを Juniper Security Director Cloud サブスクリプションに関連付ける準備ができました。

SRXシリーズファイアウォールを Juniper Security Directorクラウド サブスクリプションに関連付ける

  1. [Inventory > Devices]に移動し、デバイスを選択して、[Manage Subscriptions]をクリックします。画面の指示に従います。Manage Subscriptions interface: 1 device selected; selected subscription 10Devices S-SD-1-C-1; 1 of 10 devices in use; expires 08 Nov 2027; Add Subscriptions link; Cancel and OK buttons.
  2. サブスクリプション にデバイスのサブスクリプション名が表示されていることを確認します。 Devices management interface showing a table with columns: Host Name, Device Group, Inventory Status, Device Config Status, Management Status, Device Health, Subscriptions, OS Version, Product. Key device statuses: DEMO-AA1111AA1111 is In Sync, Up, No data for health. DEMO-TEST01 and srx111111111111 have Discovery Not Initiated, No Subscription. Buttons for Security Logs Configuration, Manage Subscriptions, and a More dropdown for additional options.

    おめでとうございます!デバイスが Juniper Security Directorクラウドに正常に関連付けられました。

Juniper Security Directorクラウドの機能を確認する

Juniper Security Direct Cloudのセットアップが開始されたので、ビジネスニーズを満たすJuniper Security Director Cloudの他の機能もご確認ください。特に役立つと思われる機能をいくつか紹介します。

表2:Juniper Security Director Cloudの機能
必要に応じて 次に

セキュリティポリシーを作成またはインポートし、セキュリティポリシーにルールを追加し、デバイスにセキュリティポリシーを展開します

セキュリティポリシーの概要を参照してください

コンテンツセキュリティプロファイルを設定して、複数のセキュリティ脅威タイプからネットワークを保護します

コンテンツセキュリティプロファイルの概要を参照してください

ATPクラウドを設定して、進化するセキュリティ脅威からネットワーク内のすべてのホストを保護

ファイル検査プロファイルの概要を参照してください

見つかったウイルス、ダウンしているインターフェイス、攻撃数、CPUの急増、システム再起動、セッションなど、トラフィックログとネットワークイベントを表示します

セッションの概要すべてのセキュリティイベントの概要を参照してください