Add and Manage Secure Edge Policy Rules
Secure Edge policy rules manage transit traffic within a context. The traffic is identified by matching its source sites, source and destination addresses, and application protocol headers with the policy database. You can also enable advanced security protection by specifying the following:
- Intrusion prevention system (IPS) profile
- Decrypt profile
- Web filtering
- Content filtering
- SecIntel group
- Anti-malware
- Cloud Access Security Broker (CASB)
Juniper Secure Edge provides the following methods to authenticate your on-premises users and devices:
-
Juniper Identity Management System (JIMS)—Deploy Juniper Identity Management System (JIMS) Collectors at your sites. JIMS fetches authenticated, domain-joined users from Active Directory and sends the details to Juniper Secure Edge service. This enables users to access applications via Juniper Secure Edge without re-authenticating, providing an optimal experience.
Note:You can get user group information without the need to deploy on-premises JIMS Collectors. Configure Identity Provider (IdP) settings in Juniper Secure Edge to fetch the information from Microsoft Entra ID (Azure AD) or Okta. Juniper Secure Edge will acquire user group details from these sources, allowing administrators to utilize this data to administer security policies effectively.
-
Captive portal—You can enable the captive portal feature to require Juniper Secure Edge to authenticate your on-premises users. This is particularly useful if you need to authenticate users who are not joined to the domain through Juniper Secure Edge, and it can serve as a backup authentication method if JIMS Collectors cannot communicate with your Active Directory servers. By default, this feature is turned off for on-premises users. Before enabling the captive portal feature, consider the following:
-
Create policy exceptions for on-premises users, like guest users, and for devices that cannot be authenticated by your Active Directory.
- Ensure that the policy exceptions are listed before the captive portal policy to grant these users or devices access through Juniper Secure Edge.
- Allocate these users and devices their own IP subnets to efficiently manage policy configurations.
-
The captive portal policy will exclusively work for traffic through browsers.
-
Set the DHCP lease time to five hours. You should renew the lease before expiration or get a new IP address if it's not renewed. If the DHCP lease is not renewed, re-authentication is needed.
-
Add Secure Edge Policy Rules
Manage Secure Edge Policy Rules
-
Edit—Select the rule, and then click the pencil icon (
).
-
Clone—Select the rule, and then click .
-
Delete—Select the rule, and then click the trash can icon (
).