Add Devices
Overview
You can add devices to Juniper Security Director in the following ways:
-
Using Commands - Juniper Security Director generates commands for adding an individual device, device cluster, or MNHA pair devices. When you copy-paste and commit the commands into the device console, the device, device cluster, or MNHA pair devices are added to Juniper Security Director. See Add Standalone Devices, Device Clusters, or MNHA Pair Devices Using Commands. For the list of supported SRX Series firewalls on which MNHA is supported, see the High Availability User Guide.
Note:Juniper Security Director supports MNHA pair devices running Junos OS Release 22.4R1 or later.
Before You Begin
Ensure that each SRX Series Firewall port can communicate with Juniper Security Director. Table 1 contains the details of SRX Series Firewall inbound connection ports.
Port |
Purpose |
---|---|
7804 |
Inbound connection from all managed devices. |
6514 |
Inbound connection for traffic logs. |
Add Standalone Devices, Device Clusters, or MNHA Pair Devices Using Commands
Juniper Security Director generates commands for adding a standalone device, a device cluster, or a multinode high availability (MNHA) pair devices. You can copy-paste and commit the commands into the device console, after which the devices are discovered and added to Juniper Security Director. For more information about MNHA, see the High Availability User Guide.
After discovery is complete, the status in the Management Status column changes to Up. If the discovery fails, Discovery failed status is displayed. Hover over the Discovery failed status to see the reason for the failure.
-
If the job fails for an MNHA pair, the deployment mode is not displayed beside the MNHA pair name. You can delete and add the MNHA pair again or initiate the discovery process again.
-
If security certificate installation job failed on a device in the MNHA pair, retry the job from the Jobs page and then reinitiate security logs configuration for the device from the Devices page.
Auto Import Behavior on Devices Added to Juniper Security Director
If you have selected the auto-import option under the Organization tab and the devices are managed using the adopt devices method and device discovery profiles, this will automatically import security policies, NAT and referred objects. See About the Organization Page.
-
The auto import process creates copies of objects that conflict with the existing objects in Juniper Security Director.
-
The auto import process does not overwrite default Content Security settings in Juniper Security Director. The existing Content Security configuration is considered instead of the imported device configuration. We recommend you review and configure the Content Security settings in Juniper Security Director before managing the device. See Configure the Content Security Settings.