Cloud Feeds for Juniper ATP Cloud
The cloud feed URL is set up automatically for you when your SRX Series Firewall is enrolled to the Juniper ATP Cloud. For more information, see Enroll an SRX Series Firewall Using the CLI and Enroll an SRX Series Firewall Using Juniper ATP Cloud Web Portal. There are no further steps you need to do to configure the cloud feed URL.
If you do not see a URL listed, run the ops script again as it configures other settings in addition to the cloud feed URL.
Once you configure your SRX Series Firewall, the cloud feeds are automatically sent from Juniper ATP Cloud to the device.
Table 1 lists the cloud feed endpoints for each region, with separate URLs for TPM-based and non‑TPM-based devices that are already enrolled, along with their source locations.
|
Region |
URL (Non-TPM-Based Devices) |
URL (TPM-Based Devices) |
Source Location |
|---|---|---|---|
|
United States |
https://cloudfeeds.sky.junipersecurity.net https://cloudfeeds-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm.sky.junipersecurity.net https://cloudfeeds-tpm-v6.sky.junipersecurity.net |
Oregon, USA |
|
European Union |
https://cloudfeeds.sky.junipersecurity.net https://cloudfeeds-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm.sky.junipersecurity.net https://cloudfeeds-tpm-v6.sky.junipersecurity.net |
Oregon, USA |
|
APAC |
https://cloudfeeds-tokyo.sky.junipersecurity.net https://cloudfeeds-tokyo-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm-tokyo.sky.junipersecurity.net https://cloudfeeds-tpm-tokyo-v6.sky.junipersecurity.net |
Tokyo, Japan |
|
Canada |
https://cloudfeeds-canada.sky.junipersecurity.net https://cloudfeeds-canada-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm-canada.sky.junipersecurity.net https://cloudfeeds-tpm-canada-v6.sky.junipersecurity.net |
Montreal, Canada |
Table 2 lists the cloud feed endpoints for each region, with separate URLs for TPM-based and non‑TPM-based devices that are newly enrolled, along with their source locations.
|
Region |
URL (Non-TPM-Based Devices) |
URL (TPM-Based Devices) |
Source Location |
|---|---|---|---|
|
United States |
https://cloudfeeds-v2.sky.junipersecurity.net https://cloudfeeds-v2-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm-v2.sky.junipersecurity.net https://cloudfeeds-tpm-v2-v6.sky.junipersecurity.net |
Oregon, USA |
|
European Union |
https://cloudfeeds-v2.sky.junipersecurity.net https://cloudfeeds-v2-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm-v2.sky.junipersecurity.net https://cloudfeeds-tpm-v2-v6.sky.junipersecurity.net |
Oregon, USA |
|
APAC |
https://cloudfeeds-v2-tokyo.sky.junipersecurity.net https://cloudfeeds-v2-tokyo-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm-v2-tokyo.sky.junipersecurity.net https://cloudfeeds-tpm-v2-tokyo-v6.sky.junipersecurity.net |
Tokyo, Japan |
|
Canada |
https://cloudfeeds-v2-canada.sky.junipersecurity.net https://cloudfeeds-v2-canada-v6.sky.junipersecurity.net |
https://cloudfeeds-tpm-v2-canada.sky.junipersecurity.net https://cloudfeeds-tpm-v2-canada-v6.sky.junipersecurity.net |
Montreal, Canada |
SRX Series Update Intervals for Cloud Feeds
Table 3 provides the update intervals for each feed type. When the SRX Series Firewall makes requests for new and updated feed content, and if there is no new content, no updates are downloaded at that time.
Run the following commands only for troubleshooting purposes:
-
The
request services security-intelligence uninstallcommand uninstalls the SecIntel service from the device. -
The
request services security-intelligence downloadcommand is used to manually initiate the download of the latest SecIntel updates before the next interval.
Things to remember:
-
Juniper Feeds—Threat intelligence feeds that Juniper provides and maintains. These feeds are available by default and help protect against known threats.
-
Integrated Feeds—Additional threat intelligence feeds that customers can enable with their license.
-
Customer Feeds—Custom feeds that customers create and manage through OpenAPI to include their own threat intelligence data, such as domains, IP addresses, or other indicators.
|
Category |
Feeds |
SRX Series Firewall Update Intervals (in Seconds) |
|---|---|---|
|
Command and Control (C&C) |
Juniper Feeds |
1,800 |
|
Integrated Feeds |
86,400 |
|
|
Customer Feeds |
60 |
|
|
GeoIP |
geoip_country |
86,400 |
|
Allowlist |
Juniper Feeds (whitelist_dns) | 1,800 |
| Juniper Feeds (whitelist_dns_umbrella) | 86,400 | |
|
Customer Feeds (domain, IP and Domain Name System (DNS)) |
1,800 |
|
| Customer Feeds (reverse shell) | 300 | |
|
Blocklist |
Customer Feeds (domain and IP) |
1800 |
|
Infected Hosts |
Infected Hosts |
60 |
| Suspicious Hosts | Suspicious Hosts | 60 |
| DNS | Juniper Feeds | 1800 |
| Customer Feeds | 60 | |
|
IPFilter |
Customer Feeds |
1,800 |
|
Third party DAG Feeds. For example, Office 365 |
1,800 |