Viewing and Synchronizing Out-of-Band IPS Policy Changes Manually
Starting in Junos Space Security Director Release 19.4R1, when there is an out-of-band IPS policy change in the device, you can see an icon next to the corresponding policy in device-specific and group IPS policies in Security Director. You can manually synchronize the out-of-band changes for a device-specific policy, only when the automatic synchronization is disabled.
When you hover over the icon next to the policy, the tooltip indicates the out-of-band changes.
For devices running Junos OS Release 18.2 and later, you can synchronize the IPS policy changes from standard or unified firewall policies page. For devices with Junos OS Release 18.1 and earlier, you can synchronize the IPS policy changes from the IPS Policies page.
When a device is discovered in Security Director, the Managed Status is displayed as Managed in the Security Devices page. For manual synchronization of out-of-band policy changes, the managed status of the device must be SD Changed, Device Changed, or In Sync. For this, you must update the device atleast once from Security Director. In case of logical system (LSYS) or tenant system (TSYS), root device may show the status as Device Changed if a policy is assigned to it. Update the root device so that the status is In Sync.
Out-of-band changes are not supported if more than one policy is assigned to a device or if rules are configured in All Devices Policy Pre/Post policies.
Viewing Out-of-Band IPS Policy Changes
To view out-of-band IPS policy changes:
Importing Out-of-Band IPS Policy Changes Manually
To import out-of-band IPS policy changes: