SRX

 View Only
last person joined: yesterday 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  SRX5600 - URL Filtering Configuratios

    This message was posted by a user wishing to remain anonymous
    Posted 16 days ago
    This message was posted by a user wishing to remain anonymous

    Hi Community,

    We need to block a specific URL on the network from Internet. The below config passes but it is giving a license warning and that license is not present under "show system licenses". Please let me know if there is another way to block a URL apart from using 'wf_key_websense_ewf' license on SRX5600.

    CONFIG:
    set security utm feature-profile web-filtering type juniper-enhanced
    set security utm utm-policy custom-utm-policy web-filtering http-profile junos-wf-enhanced-default

    set security utm custom-objects url-pattern blacklist value "https://www.youtube.com"
    set security utm custom-objects custom-url-category bad value blacklist

    set security utm feature-profile web-filtering type juniper-enhanced
    set security utm feature-profile web-filtering url-blacklist bad
    set security utm feature-profile web-filtering juniper-enhanced server port 443
    set security utm feature-profile web-filtering juniper-enhanced server port 80

    set security policies from-zone INTERNET-SZ to-zone GI-SZ policy default-permit then permit application-services utm-policy custom-utm-policy
    set security policies from-zone INTERNET-SZ to-zone INTERNET-SZ policy default-permit then permit application-services utm-policy custom-utm-policy
    set security policies from-zone GI-SZ to-zone INTERNET-SZ policy default-permit then permit application-services utm-policy custom-utm-policy



  • 2.  RE: SRX5600 - URL Filtering Configuratios

    Posted 16 days ago

    You should be able to use juniper-local web filtering without a license:

    https://www.juniper.net/documentation/us/en/software/junos/utm/topics/topic-map/security-utm-local-web-filtering.html



    ------------------------------
    Nikolay Semov
    ------------------------------