Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Supported Devices for NGFW, and Ports and Protocols to Open

Table 1 lists the Next-Generation Firewall (NGFW) devices that are supported by CSO and the list of ports or protocols that must be opened for these devices.

Note:

During the site activation process for SRX4100, SRX4200, and vSRX 3.0, you must copy the stage-1 configuration (generated automatically by CSO) to the device, and commit the configuration on the device.

Before you add a NGFW spoke site:

  • Connect cables to the device according to your network design, and power on the device. For more information, see the hardware documentation links in Table 1.

    Note:

    We assume that the NGFW device will obtain the DHCP IP address and will have Internet connectivity along with DNS resolution when connected according to the network design.

  • Ensure that the ports and protocols listed in Table 1 are open on the network.

  • Ensure that the devices are running the recommended version of Junos OS. For information about the supported Junos OS versions in a CSO release, refer to the CSO Release Notes for that release (available at the CSO Documentation page).

  • If you are using an SRX Series device as the NGFW, ensure that you configure either the first port (ge-0/0/0) or the last port (ge-0/0/7 or ge-0/0/15 based on the SRX model) for Internet connectivity.

Table 1: NGFW Devices Supported

Device Model

Protocols or Ports

Hardware Documentation Links

SRX300

SRX320

SRX340

SRX345

SRX380

TCP Port 443

TCP Port 514

TCP Port 6514

TCP Port 7804

TCP Port 8060 (only if using you are using PKI authentication to validate the certificate revocation list [CRL])

SRX300 Chassis

SRX320 Chassis

SRX340 Chassis

SRX345 Chassis

SRX380 Chassis

SRX550M

TCP Port 443

TCP Port 514

TCP Port 6514

TCP Port 7804

TCP Port 8060 (only if using you are using PKI authentication to validate the certificate revocation list [CRL])

SRX550 HM Chassis

SRX1500

TCP Port 443

TCP Port 514

TCP Port 6514

TCP Port 7804

TCP Port 8060 (only if using you are using PKI authentication to validate the certificate revocation list [CRL])

SRX1500 Chassis

SRX4100

SRX4200

TCP Port 443

TCP Port 514

TCP Port 6514

TCP Port 7804

TCP Port 8060 (only if using you are using PKI authentication to validate the certificate revocation list [CRL])

SRX4100 Chassis

SRX4200 Chassis