拠点/支社向けSRXシリーズおよびJシリーズのWebフィルタリング



Similar documents
SRXシリーズおよびJシリーズのネットワークアドレス変換

SRX IDP Full IDP Stateful Inspection 8 Detection mechanisms including Stateful Signatures and Protocol Anomalies Reassemble, normalize, eliminate ambi

Juniper Networks Corporate PowerPoint Template

SCREENOS NAT ScreenOS J-Series(JUNOS9.5 ) NAT ScreenOS J-Series(JUNOS9.5 ) NAT : Destination NAT Zone NAT Pool DIP IF NAT Pool Egress IF Loopback Grou

Dynamic VPN Dynamic VPN IPSec VPN PC SRX IPSec VPN SRX PC IPSec 2 Copyright 2010 Juniper Networks, Inc.

Junos Space

Microsoft Word - D JP.docx

SRX300 Line of Services Gateways for the Branch

Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

契約№2020-XXXX

Junos Pulse Mobile Security Dashboard Juniper Networks, Inc North Mathilda Avenue Sunnyvale, California Copyr

Juniper Networks Corporate PowerPoint Template

IPSEC-VPN IPsec(Security Architecture for Internet Protocol) IP SA(Security Association, ) SA IKE IKE 1 1 ISAKMP SA( ) IKE 2 2 IPSec SA( 1 ) IPs

Cisco ASA Firepower ASA Firepower

FW Migration Guide (Single)

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

Copyright 2008 All Rights Reserved 2

ハピタス のコピー.pages

相続支払い対策ポイント

150423HC相続資産圧縮対策のポイント

Oracle Application Server 10g( )インストール手順書

<Documents Title Here>

Systemwalker IT Service Management Systemwalker IT Service Management V11.0L10 IT Service Management - Centric Manager Windows

PowerPoint プレゼンテーション

Zurich, CH Brussels, BE Wrocław, PO Toronto, CA Ottawa, CA Herzliya, IL Almaden, US Boulder, US Detroit, US TJ Watson, US Tokyo, JP Tokyo, JP Atlanta,

SRX License

初心者にもできるアメブロカスタマイズ新2016.pages

Oracle Application Server 10g(9

- 2 Copyright (C) All Rights Reserved.

Copyright 2008 NIFTY Corporation All rights reserved. 2

Oracle Application Server10g (9.0.4) - OracleAS PortalによるOracleAS Web Cacheの配置

untitled

untitled

Packet Tracer: 拡張 ACL の設定 : シナリオ 1 トポロジ アドレステーブル R1 デバイスインターフェイス IP アドレスサブネットマスクデフォルトゲートウェイ G0/ N/A G0/

Fortigate Ver.4.0MR3Patch12 Information 1

memo ii

実施していただく前に

Copyright All Rights Reserved. -2 -!

IPA:セキュアなインターネットサーバー構築に関する調査


Microsoft Word - 最終版 バックせどりismマニュアル .docx

FortiGate Ver.4.0MR3Patch14 Information 1

Microsoft, Windows Microsoft Corporation

橡ボーダーライン.PDF

2 BIG-IP 800 LTM v HF2 V LTM L L L IP GUI VLAN.

Juniper NetworksJunosSteel-Belted RadiusNetScreenScreenOS Juniper Networks, Inc. Juniper Networks Junos JunosE Juniper Networks, Inc. Juniper Networks

ユーザーズマニュアル

Copyright Qetic Inc. All Rights Reserved. 2

Releases080909

Campus LAN Design Guide

- 2 Copyright (C) All Rights Reserved.


Tab 5, 11 Tab 4, 10, Tab 3, 9, 15Tab 2, 8, 14 Tab 1, 7, 13 2

untitled

untitled

IP IP All contents are Copyright (c) All rights reserved. Important Notices and Privacy Statement. page 2 of 39

Web Microsoft 2008 R2 Database Database!! Database 04 08

基本操作ガイド

Web Web Web Web Web, i

ScreenOS Copyright (C) 2005 NOX Co., Ltd. All Rights Reserved. Version1.00

日本語タイトルを入力

IP ( ) IP ( ) IP DNS Web Web DNS Web DNS DNS 利用者 1 利用者 2 東京都調布市の天気情報を応答 東京都調布市の天気を問い合わせ 北海道旭川市の天気を問い合わせ 北海道旭川市の天気情報を応答 Fig. 1 1 DNS サーバ 東京都調布市の天気情報 We

操作ガイド(本体操作編)

JABRA BT

how-to-decide-a-title

JP1/Integrated Management - Service Support 操作ガイド

URL AdobeReader Copyright (C) All Rights Reserved.

Oracle Identity Managementの概要およびアーキテクチャ

URL ACL(Enhanced)導入ガイド

Copyright SATO International All rights reserved. This software is based in part on the work of the Independen

VE-GD21DL_DW_ZB

操作ガイド(本体操作編)

DocuWide 2051/2051MF 補足説明書

fx-9860G Manager PLUS_J

MIDI_IO.book

Introduction Purpose This training course describes the configuration and session features of the High-performance Embedded Workshop (HEW), a key tool

スライド 1

IOS ゾーン ベースのポリシー ファイアウォールを使用した IOS ルータでの AnyConnect VPN クライアントの設定例

健康保険組合のあゆみ_top

リバースマップ原稿2

Zurich, CH Brussels, BE Wrocław, PO Toronto, CA Ottawa, CA Herzliya, IL Almaden, US Detroit, US Tokyo, JP Boulder, US TJ Watson, US Tokyo, JP Atlanta,

<Documents Title Here>

WS-I Basic Profile 1.0 の概説

RTX830 取扱説明書

GA-1190J

クラウド時代のインフラ構成/変更管理とコンプライアンス管理

IP.dvi

Windows Phone 用 Cisco AnyConnect セキュアモビリティクライ アントユーザガイド(リリース 4.1.x)

"CAS を利用した Single Sign On 環境の構築"


Jシリーズおよび拠点/支社向けSRXシリーズのイーサネットスイッチング設定ガイド

Web Web ID Web 16 Web Web i

アプリケーション アクセラレー ションおよび最適化の設定情報 と統計情報の表示

owners.book

Microsoft Word - Win-Outlook.docx

,,, J-SOX ISMS PCIDSS,, IM/VoIP/VoD Copyright 2008 Juniper Networks, Inc. 2

VE-GP32DL_DW_ZA

BRANCH SRX <2010Q3 > 2 Copyright 2010 Juniper Networks, Inc.

FileMaker Server Getting Started Guide

基本操作ガイド

Transcription:

APPLICATION NOTE SRX J WEB SRX J Web Copyright 2014, Juniper Networks, Inc.

...3...3...3...3...3...3 SurfControl Web...3 Websense Web......................................................................................4...5...5...6...8 SurfControl...8...9...11...12 Websense...13...15...15...15...15 1 SurfControl...3 2 Websense...4 3 UTM...6 4...8 2 Copyright 2014, Juniper Networks, Inc.

Web /URL UTM Unified Threat Management Web 2.0 URL Web Web URL Junos OS 9.5 J SRX UTM Web UTM 1 URL URL SurfControl Websense 2 Web J SRX SRX SRX100 SRX210 SRX240 SRX650 J2320 J2350 J4350 J6350 J Junos OS 9.5 Web SurfControl Websense 2 SRX J Web SurfControl Web Web URL SurfControl SurfControl Web J SRX URL SurfControl Web SurfControlサーバー URLルックアップ カテゴリ インターネット クライアント HTTP 要 求 SRX210 1 SurfControl Webサーバー Copyright 2014, Juniper Networks, Inc. 3

SurfControl URL 2600 40 70 SurfControl 1 SurfControl Web SRX J STRM Security Threat Response Manager URL SurfControl IPS Websense Web 1 Websense Websense SurfControl URL Websense Websense Web Websense URL SRX J URL 2 Websense HTTP 要 求 SRX210 インターネット トラフィック リダイレクト Webサーバー Websenseサーバー 4 Copyright 2014, Juniper Networks, Inc.

Websense 95 100 Websense HTTPS URL URL URL URL URL URL URL URL URL URL URL URL SurfControl Websense SurfControl SurfControl Websense "show system license" pato@srx210-1# run show system license License usage: Licenses Licenses Licenses Expiry Feature name used installed needed av_key_kaspersky_engine 1 1 0 2009-11-20 00:00:00 UTC anti_spam_key_symantec_sbl 0 1 0 2009-11-20 00:00:00 UTC wf_key_surfcontrol_cpa 0 1 0 2009-11-20 00:00:00 UTC idp-sig 0 1 0 2009-11-20 00:00:00 UTC Copyright 2014, Juniper Networks, Inc. 5

Web UTM 1 UTM UTM HTTP Web ポリシールックアップ 順 序 付 けされた ルックアップ ( 送 信 元 / 宛 先 ゾーン 毎 に インデックス 付 加 ) ポリシー1... ポリシーのマッチング UTMポリシー ポリシーN セキュリティポリシー UTMポリシーを 指 定 して トラフィックを アプリケーション サービスに 送 信 WFプロファイル 3 UTM UTM UTM Web UTM Web UTM UTM security { utm-policy <policy name> { anti-spam { anti-virus { content-filtering { http-profile <web-filtering profile name>; Web [security utm feature-profiles] security { feature-profile { url-blacklist <black-list user defined category>; url-whitelist <white-list user defined category>; type surf-control-integrated websense-redirect; surf-control-integrated { cache { size <max number of entries in the cache>; timeout <time, in seconds, after which an entry is declared invalid>; profile <profile name> { category <category name> { #One or more categories are allowed action block log-and-permit permit; custom-block-message <block-message>; default block log-and-permit permit; fallback-settings { ; timeout <request timeout in seconds>; 6 Copyright 2014, Juniper Networks, Inc.

traffic>; websense-redirect profile <profile-name>{ account <account-name>; custom-block-message <block-message>; fallback-settings { server { host <host-name or IP address>; port <server port>; sockets <number of open sockets used to redirect timeout <redirect timeout in seconds>; [security utm custom-objects] SurfControl security { custom-objects { utl-pattern <url pattern name> { value [<list of URLs>]; custom-url-category <category name> { value [<list of url-paterns>]; URL URL www.juniper.net URL www.juniper.net/ support www.juniper.net/products URL URL www.juniper. net/techpubs URL www.juniper.net/techpubs/software www.juniper.net Copyright 2014, Juniper Networks, Inc. 7

IP SurfControl 4 SurfControl Trust Zone Untrust Zone SRX210 インターネット 4 Web SurfControl security { policies { from-zone trust to-zone untrust { policy match { source-address any; destination-address any; application any; then { permit { application-services { utm-policy wf-block-specfic-categories; feature-profile { type surf-control-integrated; #This causes the device to use # the surfcontrol integrated solution surf-control-integrated { profile block-selected-sites { category { Criminal_Skills { 8 Copyright 2014, Juniper Networks, Inc.

Remote_Proxies { Violence { Weapons { default permit; utm-policy wf-block-specfic-categories { http-profile block-selected-sites; IT www.badsite.com www. addictivesite.com URL bad-sites URL custom-objects { url-pattern { badsite { value www.badsite.com; addictivesite { value www.addictivesite.com; custom-url-category { bad-sites { value [ addictivesite badsite ]; Copyright 2014, Juniper Networks, Inc. 9

Web policies { from-zone trust to-zone untrust { policy match { source-address any; destination-address any; application any; then { permit { application-services { utm-policy wf-block-specfic-categories; feature-profile { url-blacklist bad-sites; #This causes sites in the bad-sites category type surf-control-integrated; surf-control-integrated { profile block-selected-sites { category { Criminal_Skills { Remote_Proxies { Violence { Weapons { default permit; utm-policy wf-block-specfic-categories { http-profile block-selected-sites; #to be blocked 10 Copyright 2014, Juniper Networks, Inc.

Web "The site requested is not a work-related site.go back to work! " policies { from-zone trust to-zone untrust { policy match { source-address any; destination-address any; application any; then { permit { application-services { utm-policy wf-block-specfic-categories; feature-profile { url-blacklist bad-sites; type surf-control-integrated; surf-control-integrated { profile block-selected-sites { category { Criminal_Skills { Remote_Proxies { Violence { Weapons { default permit; custom-block-message The site requested is not a workrelated site!go back to work! ; utm-policy wf-block-specfic-categories { http-profile block-selected-sites; Copyright 2014, Juniper Networks, Inc. 11

2 Web security { policies { from-zone trust to-zone management { policy webfilter-on-business-hours { match { source-address any; destination-address any; application any; then { permit { application-services { utm-policy wf-block-specfic-categories; scheduler-name Business-hours; policy accept-all { match { source-address any; destination-address any; application any; then { permit; feature-profile { url-blacklist bad-sites; type surf-control-integrated; surf-control-integrated { profile block-selected-sites { category { Criminal_Skills { Remote_Proxies { Violence { Weapons { default permit; custom-block-message The site requested is not a workrelated site!go back to work! ; 12 Copyright 2014, Juniper Networks, Inc.

utm-policy wf-block-specfic-categories { http-profile block-selected-sites; schedulers { scheduler Business-hours { daily { start-time 09:00:00 stop-time 17:00:00; sunday exclude; saturday exclude; Websense Websense Web SRX J Websense policies { from-zone trust to-zone management { policy webfilter-websense { match { source-address any; destination-address any; application any; then { permit { application-services { utm-policy wf-redirect; feature-profile { type websense-redirect; websense-redirect { profile server1-redirect { server { host 10.1.1.100; port 15868; custom-block-message Websense says... you are not allowed! ; sockets 3; Copyright 2014, Juniper Networks, Inc. 13

utm-policy wf-redirect { http-profile server1-redirect; sockets Junos OS Websense Websense SurfControl policies { from-zone trust to-zone management { policy webfilter-websense { match { source-address any; destination-address any; application any; then { permit { application-services { utm-policy wf-redirect; feature-profile { type websense-redirect; websense-redirect { profile server1-redirect { server { host 10.1.1.100; port 15868; custom-block-message Websense says... you are not allowed! ; fallback-settings { default block; too-many-requests log-and-permit; sockets 8; utm-policy wf-redirect { http-profile server1-redirect; 14 Copyright 2014, Juniper Networks, Inc.

>show security utm web-filtering statistics UTM web-filtering statistics: Total requests: 0 white list hit: 0 Black list hit: 0 Server reply permit: 0 Server reply block: 0 Web-filtering sessions in total:4000 Web-filtering sessions in use: 0 Fall back: log-and-permit block Default 0 0 Timeout 12 0 Connectivity 0 0 Too-many-requests 0 0 2 30 40 50 URL 15 20 30 URL URL 500 1000 1500 / URL 8192 8192 8192 URL 29 29 29 URL 512 512 512 29 29 29 Junos OS 9.5 SRX J Web URL http://www.juniper.net/jp/ Twitter Facebook Copyright 2014, Juniper Networks, Inc. 15

Juniper Networks, Inc. Juniper Networks International B.V. 163-1445 3-20-2 45F 03-5333-7400 FAX 03-5333-7401 541-0041 1-1-27 URL http://www.juniper.net/jp/ 1194 North Mathilda Ave Sunnyvale, CA 94089 USA 888-JUNIPER (888-586-4737) 408-745-2000 FAX 408-745-2100 URL http://www.juniper.net Boeing Avenue 240 1119 PZ Schiphol-Rijk Amsterdam, The Netherlands 31-0-207-125-700 FAX 31-0-207-125-701 Copyright 2014, Juniper Networks, Inc. All rights reserved. Juniper Networks Junos QFabric Juniper Networks Juniper Networks, Inc. 3500156-002 JP Apr 2014 16 Copyright 2014, Juniper Networks, Inc.