Product Compatibility
This section describes the supported hardware and software versions for Policy Enforcer. For Security Director requirements, see Junos Space Security Director Release Notes.
Supported Security Director Software Versions
Policy Enforcer is supported only on specific Security Director software versions as shown in Table 1.
Policy Enforcer Software Version |
Compatible with Security Director Software Version |
Junos OS Release (Juniper ATP Cloud Supported Devices) |
---|---|---|
23.1R1 |
23.1R1 |
Junos OS Release 15.1X49-D120 or Junos OS Release 17.3R1 and later |
The times zones set for Security Director and Policy Enforcer must be the same.
Supported Devices
Table 2 lists the SRX Series devices that support Juniper ATP Cloud and the threat feeds these devices support.
Platform |
Model |
Junos OS Release |
Supported Threat Feeds |
---|---|---|---|
vSRX |
2 vCPUs, 4GB RAM |
Junos 15.1X49-D60 and later |
C&C, antimalware, infected hosts, GeoIP |
SRX Series |
SRX300, SRX320 |
Junos 15.1X49-D90 and later |
C&C, GeoIP |
SRX Series |
SRX340, SRX345, SRX550M |
Junos 15.1X49-D60 and later |
C&C, antimalware, infected hosts, GeoIP |
SRX Series |
SRX1500 |
Junos 15.1X49-D60 and later |
C&C, antimalware, infected hosts, GeoIP |
SRX Series |
SRX5400, SRX5600, SRX5800 |
Junos 15.1X49-D62 and later |
C&C, antimalware, infected hosts, GeoIP |
SRX Series |
SRX4100, SRX4200 |
Junos 15.1X49-D65 and later |
C&C, antimalware, infected hosts, GeoIP |
SRX Series |
SRX4600 |
Junos 18.1R1 and later |
C&C, antimalware, infected hosts, GeoIP |
SRX Series |
SRX3400, SRX3600 |
Junos 12.1X46-D25 and later |
C&C, GeoIP |
SRX Series |
SRX1400 |
Junos 12.1X46-D25 and later |
C&C, GeoIP |
SRX Series |
SRX550 |
Junos 12.1X46-D25 and later |
C&C, GeoIP |
SRX Series |
SRX650 |
Junos 12.1X46-D25 and later |
C&C, GeoIP |
Table 3 describes the hardware and software components that are compatible with JATP.
Platform |
Hardware |
Software Versions |
---|---|---|
vSRX |
Junos 19.1R1.6 and above |
|
SRX Series |
SRX320, SRX300 |
Junos 19.1R1 and above |
SRX Series |
SRX4100, SRX4200, SRX4600 |
Junos 15.1X49-D65 and above for SRX4100 and SRX4200 Junos 18.1R1 and above for SRX4600 |
SRX Series |
SRX340, SRX345, SRX550m |
Junos 15.1X49-D60 and above |
SRX Series |
SRX5800, SRX5600, SRX5400 |
Junos 15.1X49-D50 and above |
SRX Series |
SRX1500 |
Junos 15.1X49-D33 and above |
The SMTP e-mail attachment scan feature is supported only on the SRX1500, SRX4100, SRX4200, SRX5400, SRX5600, and SRX5800 devices running Junos OS Release 15.1X49-D80 and later. vSRX does not support the SMTP e-mail attachment scan feature.
In Policy Enforcer Release 18.3R1, Policy Enforcer supports SRX Series devices running Junos OS Release 17.3R1 and later.
Table 4 lists the supported EX Series and QFX Series switches.
Platform |
Model |
Junos OS Release |
---|---|---|
EX Series |
EX4200, EX2200, EX3200, EX3300, EX4300 |
Junos 15.1R6 and later |
EX Series |
EX9200 |
Junos 15.1R6 and later |
EX Series |
EX3400, EX2300 |
Junos 15.1R6 and later Junos 15.1X53-D57 and later |
QFX Series |
QFX5100, QFX5200 vQFX |
Junos 15.1R6 and later Junos 15.1X53-D60.4 |
Table 5 lists the supported MX Series routers that support the DDoS and C&C feed types.
Platform |
Model |
Junos OS Release |
Supported Feed Types |
---|---|---|---|
MX Series |
MX240, MX480, MX960 |
Junos 14.2R1 and later |
DDoS |
MX240, MX480, MX960 |
Junos 18.4R1 and later |
C&C (Mark MX Series router as perimeter device in secure fabric). The C&C feed is global and is overridden if the C&C custom feed is set on Policy Enforcer. |
|
vMX |
Junos 16.2R2.8 |
- |
Table 6 shows the supported SDN and cloud platforms.
Component |
Specification |
---|---|
VMware NSX for vSphere |
6.3.1 and later Note:
For sites that are running vSphere 6.5, vSphere 6.5a is the minimum supported version with NSX for vSphere 6.3.0. |
VMware NSX Manager |
6.3.1 and later |
Third-Party Wired and Wireless Access Network
Table 7 lists the third-party support and required server.
Switch/Server |
Notes |
---|---|
Third-party switch |
Any switch model that adheres to RADIUS IETF attributes and supports RADIUS Change of Authorization from ClearPass is supported by Policy Enforcer for threat remediation. |
ClearPass RADIUS server |
Must be running software version 6.6.0. |
Cisco ISE |
Must be running software version 2.1 or 2.2. |
Forescout CounterACT |
Must be running software version 7.0.0. Note:
To obtain an evaluation copy of CounterACT for use with Policy Enforcer. |
Pulse Secure |
Must be running software version 9.0R3. |
If you use Juniper Networks EX4300 Ethernet switch to integrate with the third-party switches, the EX4300 must be running Junos OS Release 15.1R6 or later.
Juniper Networks Contrail, Microsoft Azure, and AWS Specifications
Table 8 shows the required components for Juniper Networks Contrail.
Model |
Software Version |
Supported Policy Enforcer Mode |
---|---|---|
Juniper Networks Contrail |
5.0 |
Microsegmentation and threat remediation with vSRX |
vSRX |
Junos OS 15.1X49-D120 and later |
Microsegmentation and threat remediation with vSRX |
Table 9 shows the required Policy Enforcer components for AWS.
Model |
Software Version |
Supported Policy Enforcer Mode |
---|---|---|
vSRX |
Junos OS 15.1X49-D100.6 and later Junos OS 19.2R1 and later |
vSRX policy based on workload discovery AWS with JATP |
To get started with Microsoft Azure, see Getting Started with Microsoft Azure.
Table 10 shows the required Policy Enforcer components for Microsoft Azure.
Model |
Software Version |
Supported Policy Enforcer Mode |
---|---|---|
vSRX |
Junos OS 15.1X49-D110.4 and later |
vSRX policy based on workload discovery |
Virtual Machine
Policy Enforcer is delivered as an open virtual appliance (OVA) or a kernel-based virtual machine (KVM) package to be deployed inside your VMware ESX or Quick Emulator (QEMU)/KVM network with the following configuration:
-
4 CPUs
-
16 GB RAM
-
300 GB disk space
Virtual Machine |
Version |
---|---|
VMware |
VMware ESX server version 4.0 or later or a VMware ESXi server version 4.0 or later |
QEMU/KVM |
CentOS Release 7.9 or later |
Supported Browser Versions
Security Director and Policy Enforcer are best viewed on the following browsers.
Browser |
Version |
---|---|
Google Chrome |
75.x |
Firefox |
67.0 and later |
Upgrade Support
You can upgrade to Policy Enforcer Release 23.1R1 from Policy Enforcer Release 22.3R1.
For complete upgrade instructions, see Upgrading Your Policy Enforcer Software.
For more information about the Security Director upgrade path, see Upgrading Security Director.