
Chapter 4 Resetting the SRX Series Device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
ResettingtheBranchSRXSeries.......................................27
ResettingYourBranchSRXSeries..................................27
Resetting Your SRX Series to a Rescue Configuration . . . . . . . . . . . . . . . 27
Resetting Your SRX Series to Factory Settings . . . . . . . . . . . . . . . . . . . . . 27
Part 3 Configuring Basic SRX Series Features
Chapter 5 Configuring Security Zones and Policies for SRX Series . . . . . . . . . . . . . . . . . 31
Understanding Security Zones and Policies for SRX Series . . . . . . . . . . . . . . . . . . 31
Zones .........................................................31
SecurityPolicy..................................................32
Example: Configuring Security Zones and Policies for SRX Series . . . . . . . . . . . . . 32
Chapter6 ConfiguringNATforSRXSeries.....................................39
UnderstandingNATforSRXSeries.....................................39
Example: Configuring Destination NAT for SRX Series . . . . . . . . . . . . . . . . . . . . . 40
Chapter 7 Managing Licenses for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Updating Licenses for a Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Chapter 8 Configuring UTM for Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
Understanding Unified Threat Management for Branch SRX Series . . . . . . . . . . . 49
Example: Configuring Unified Threat Management for a Branch SRX Series . . . . . 51
Default UTM Policy for Branch SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
DefaultUTMPolicy..............................................54
Predefined UTM Profile Configuration for Branch SRX Series . . . . . . . . . . . . . . . . 54
Antispam......................................................54
Antivirus ......................................................55
WebFiltering...................................................56
Chapter 9 Configuring Intrusion Detection and Prevention for SRX Series . . . . . . . . . 63
Understanding Intrusion Detection and Prevention for SRX Series . . . . . . . . . . . . 63
Example: Configuring Intrusion Detection and Prevention for SRX Series . . . . . . 64
Chapter 10 Understanding Stateful Firewall, IPsec VPN, and Chassis Cluster for
BranchSRXSeries.................................................71
Understanding Branch SRX Series Stateful Firewall Functionality . . . . . . . . . . . . . 71
Understanding IPsec VPN for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
Understanding Chassis Cluster for SRX Series . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
Part 4 Configuration Statements and Operational Commands
Chapter11 ConfigurationStatements..........................................75
Security Configuration Statement Hierarchy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
[edit security address-book] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
[editsecurityidp]HierarchyLevel......................................77
[editsecurityike]HierarchyLevel......................................87
[editsecurityipsec]HierarchyLevel....................................88
[editsecuritynat]HierarchyLevel.....................................90
[edit security policies] Hierarchy Level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93
Copyright © 2016, Juniper Networks, Inc.iv
Getting Started Guide for Branch SRX Series