Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Create and Manage Metadata Streaming Profiles to Detect all DNS Threats

Create Metadata Streaming Profiles

  1. In the Metadata Streaming Profiles section, click the plus icon (Blue plus symbol suggesting an action like adding or expanding content.).
    The Create Metadata Streaming Profile page is displayed.
  2. Enter a unique profile name within 63 alphanumeric characters. You can use special characters such as _ and -.
  3. In the DNS section, enable the All toggle button. When you enable this option, you cannot configure detection of domain generation algorithm (DGA) based threats and DNS tunnels.
  4. Select the action that must be performed if a threat is detected:
    • Deny—Drop the session.

    • Sinkhole—Drop the session and sinkhole the request domain.

      Note:

      To sinkhole a request domain, you must configure the sinkhole settings for the device. To configure the settings from Juniper Security Director Cloud, click the device name on the Devices page and then click Junos Detailed Configurations > Services > Dns Filtering > Sinkhole.

    • Permit—Permit the session.

  5. Select how you want to log a request:
    • Log detections—Log the request only if a threat is detected.

    • Log everything—Log all requests received by the device.

  6. Enable the Fallback options log toggle button to log the request if no threat is detected.
  7. To store DNS requests in cache, enable the Cache TTL toggle button and enter the duration for which requests from benign and command-and-control (C2) domains must be stored.
  8. Click OK.
    The metadata streaming profile is created and displayed on the Metadata Streaming Policy page.

Manage Metadata Streaming Profiles

  • Edit—Select the profile, and then click the pencil icon (Blue pencil icon indicating edit functionality.).

  • Clone—Select the profile, and then click More > Clone.

    Note:

    By default, the profile name is suffixed with _copy_1.

  • Delete—Select the profile, and then click the trash can icon (Blue trash can icon representing delete or remove function.).