Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Security Policies Overview

Security Policies define how network traffic is managed across SRX Series Firewalls. These policies are centrally created in Juniper Security Director Cloud and enforced consistently across devices.

Security policies define rules that determine whether traffic to devices is allowed, blocked, inspected, or limited based on conditions. Beyond allowing or denying traffic, security policies can combine multiple criteria listed in this table from the Transport Layer (Layer 4) and Application Layer (Layer 7) of the OSI model into a single rule.

Table 1: Network Layer-Specific Traffic Monitored
Layer Information
Network transport (Layer 4)
  • Source and destination IP addresses
  • Source and destination ports
  • Protocols such as TCP, UDP, and ICMP
Application (Layer 7)
  • Specific applications such as Office 365, Dropbox, and SSH
  • Application functions such as file upload or chat within the same app
  • URL categories such as social media, gambling, and malware sites

This combination of Layer 4 and Layer 7 criteria allows organizations to create more precise, context‑aware controls than traditional port‑based rules alone.

Security policies can directly match traffic based on applications, such as web, e-mail, or collaboration apps, in addition to basic conditions such as IP addresses and ports. This means you can control application traffic within the same policy rule, instead of creating separate configurations for applications.

Security Policy Workflow

This workflow shows how to create security policies.

Security Policy Workflow
Category Task More Information

Prerequisites

Before you add a security policy, complete these tasks.

  • Define the security policy objective.

  • Identify the devices to deploy the security policy.

  • Verify the devices are onboarded.

Configure a security policy

  • Either create a new security policy or import security policies from a device.

  • Configure the default security settings and subscriptions.

Configure a security policy rule

  • Either create a global security policy rule or a zone-based policy rule.

  • Configure the security policy rule.

Add and Manage Security Policy Rules
Review the security policy
  • Verify the selected devices to deploy the policy.

  • Verify that the policy is positioned correctly in the overall policy list so it aligns with the intended order of execution and dependencies between policies.

Deploy the security policy

Choose whether to deploy the policy on all devices or only those devices that require the policy update.

Deploy Security Policies

Security Policy Benefits

  • Traffic action control—Permits, rejects, denies, redirects, or tunnels the traffic based on the identified application.
  • Application-aware traffic recognition—Recognizes not just HTTP traffic but also any applications operating over it, which helps in enforcing policies effectively. For instance, a security rule for applications might block HTTP traffic originating from Facebook while permitting HTTP web access to Microsoft Outlook.
  • Advanced security services integration—Provides advanced security protection by specifying the following profiles—Intrusion prevention system (IPS) profile, Content security profile, SSL proxy profile.
  • Flexible rule categorization—Categorizes rules as zone-based rules and global rules.

    • Zone-based-rules are rules with zones as source and destination endpoints.

    • Global rules give the flexibility to perform actions on the traffic without any zonal restrictions.

Security Policy Placement

Security policies and security policy rules execute in the sequence they are displayed on the Security Policies page.

  • Policy order is important.
  • New policies go to the end of the policy list.
  • The last policy is the default policy, which has the default action of denying all traffic.

When you configure multiple security policies, one policy might eclipse, or shadow, another policy. In such cases, change the order of the policies and place more specific policies before generic policies.

Example

As shown in the illustration, on a device with multiple security policies, deployment follows the ascending sequence number for the zone pair. For example, consider two security policies, P1 and P2, assigned to Device 1.

  • On Device 1, policy P2 has sequence 1 and policy P1 has sequence 2.

  • Both policies operate from the untrust zone to the trust zone—P1 includes Rule a, and P2 includes Rule b.

  • When you deploy the policies, the deployment order is P2 (sequence 1) first, then P1 (sequence 2).

Figure 1: Security Policy Sequence-Based Deployment Image illustrating the sequence-based deployment of security policies

Security Policies Field Descriptions

You can create, edit, and remove security policies that are linked to devices. To access this page, select Security > Security Policies.

Table 2: Fields on the Security Policies Page

Field

Description

Seq.

The order number of the security policy.

Name

The name of the security policy.

Rules

The number of rules associated with the security policy.

If no rule is associated with the policy, Add Rule is displayed. See Add and Manage Security Policy Rules

Devices

The number of devices associated with the security policy.

Status

The deployment status of the security policy.

  • Deploy Successful
  • Deploy Pending
  • Deploy Failed
  • Deploy scheduled
  • Deploy in progress
  • Redeploy required

Modified By

The user who modified the security policy.

Last Modified

The date and time when the security policy was modified.

Description

The description of the security policy.