Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Cloud Feeds for Juniper ATP Cloud

The cloud feed URL is set up automatically for you when your SRX Series Firewall is enrolled to the Juniper ATP Cloud. For more information, see Enroll an SRX Series Firewall Using the CLI and Enroll an SRX Series Firewall Using Juniper ATP Cloud Web Portal. There are no further steps you need to do to configure the cloud feed URL.

If you do not see a URL listed, run the ops script again as it configures other settings in addition to the cloud feed URL.

Once you configure your SRX Series Firewall, the cloud feeds are automatically sent from Juniper ATP Cloud to the device.

Table 1 lists the cloud feed endpoints for each region, with separate URLs for TPM-based and non‑TPM-based devices that are already enrolled, along with their source locations.

Table 1: Cloud Feed Regions and URLs

Region

URL (Non-TPM-Based Devices)

URL (TPM-Based Devices)

Source Location

United States

https://cloudfeeds.sky.junipersecurity.net

https://cloudfeeds-v6.sky.junipersecurity.net

https://cloudfeeds-tpm.sky.junipersecurity.net

https://cloudfeeds-tpm-v6.sky.junipersecurity.net

Oregon, USA

European Union

https://cloudfeeds.sky.junipersecurity.net

https://cloudfeeds-v6.sky.junipersecurity.net

https://cloudfeeds-tpm.sky.junipersecurity.net

https://cloudfeeds-tpm-v6.sky.junipersecurity.net

Oregon, USA

APAC

https://cloudfeeds-tokyo.sky.junipersecurity.net

https://cloudfeeds-tokyo-v6.sky.junipersecurity.net

https://cloudfeeds-tpm-tokyo.sky.junipersecurity.net

https://cloudfeeds-tpm-tokyo-v6.sky.junipersecurity.net

Tokyo, Japan

Canada

https://cloudfeeds-canada.sky.junipersecurity.net

https://cloudfeeds-canada-v6.sky.junipersecurity.net

https://cloudfeeds-tpm-canada.sky.junipersecurity.net

https://cloudfeeds-tpm-canada-v6.sky.junipersecurity.net

Montreal, Canada

Table 2 lists the cloud feed endpoints for each region, with separate URLs for TPM-based and non‑TPM-based devices that are newly enrolled, along with their source locations.

Table 2: Cloud Feed Regions and URLs for Newly Enrolled Devices

Region

URL (Non-TPM-Based Devices)

URL (TPM-Based Devices)

Source Location

United States

https://cloudfeeds-v2.sky.junipersecurity.net

https://cloudfeeds-v2-v6.sky.junipersecurity.net

https://cloudfeeds-tpm-v2.sky.junipersecurity.net

https://cloudfeeds-tpm-v2-v6.sky.junipersecurity.net

Oregon, USA

European Union

https://cloudfeeds-v2.sky.junipersecurity.net

https://cloudfeeds-v2-v6.sky.junipersecurity.net

https://cloudfeeds-tpm-v2.sky.junipersecurity.net

https://cloudfeeds-tpm-v2-v6.sky.junipersecurity.net

Oregon, USA

APAC

https://cloudfeeds-v2-tokyo.sky.junipersecurity.net

https://cloudfeeds-v2-tokyo-v6.sky.junipersecurity.net

https://cloudfeeds-tpm-v2-tokyo.sky.junipersecurity.net

https://cloudfeeds-tpm-v2-tokyo-v6.sky.junipersecurity.net

Tokyo, Japan

Canada

https://cloudfeeds-v2-canada.sky.junipersecurity.net

https://cloudfeeds-v2-canada-v6.sky.junipersecurity.net

https://cloudfeeds-tpm-v2-canada.sky.junipersecurity.net

https://cloudfeeds-tpm-v2-canada-v6.sky.junipersecurity.net

Montreal, Canada

SRX Series Update Intervals for Cloud Feeds

Table 3 provides the update intervals for each feed type. When the SRX Series Firewall makes requests for new and updated feed content, and if there is no new content, no updates are downloaded at that time.

Note:

Run the following commands only for troubleshooting purposes:

  • The request services security-intelligence uninstall command uninstalls the SecIntel service from the device.

  • The request services security-intelligence download command is used to manually initiate the download of the latest SecIntel updates before the next interval.

Things to remember:

  • Juniper Feeds—Threat intelligence feeds that Juniper provides and maintains. These feeds are available by default and help protect against known threats.

  • Integrated Feeds—Additional threat intelligence feeds that customers can enable with their license.

  • Customer Feeds—Custom feeds that customers create and manage through OpenAPI to include their own threat intelligence data, such as domains, IP addresses, or other indicators.

Table 3: Feed Update Intervals

Category

Feeds

SRX Series Firewall Update Intervals (in Seconds)

Command and Control (C&C)

Juniper Feeds

1,800

Integrated Feeds

86,400

Customer Feeds

60

GeoIP

geoip_country

86,400

Allowlist

Juniper Feeds (whitelist_dns) 1,800
Juniper Feeds (whitelist_dns_umbrella) 86,400

Customer Feeds (domain, IP and Domain Name System (DNS))

1,800

Customer Feeds (reverse shell) 300

Blocklist

Customer Feeds (domain and IP)

1800

Infected Hosts

Infected Hosts

60

Suspicious Hosts Suspicious Hosts 60
DNS Juniper Feeds 1800
Customer Feeds 60

IPFilter

Customer Feeds

1,800

Third party DAG Feeds. For example, Office 365

1,800