Juniper SRX AppSecure: AppID and UTM Policy Setup - 夜莺博客

Juniper SRX AppSecure: AppID and UTM Policy Setup

A port-based security policy on an SRX is easy to write and increasingly useless: HTTPS on 443, tunnelled applications, and micro-applications inside legitimate sessions all defeat it. AppSecure fixes that by identifying traffic by behaviour rather than port. This article covers the three pieces that matter operationally — Application Identification (AppID), AppTrack for visibility, and unified policies that attach UTM profiles for antivirus, web filtering and content filtering — and the order in which to deploy them so you get visibility before you get enforcement.

The AppSecure Toolkit

  • AppID (Application Identification) classifies traffic at multiple layers, ignoring port and protocol, and recognises nested applications riding inside trusted services.
  • AppTrack records which applications pass through the device and produces logging and reports. This is the visibility layer and it enforces nothing.
  • Application Firewall with unified policies permits, rejects or denies traffic based on the identified application.
  • AppQoS applies QoS prioritisation based on the application identity.

Stage 1 — Enable AppID

Application identification has to be on before anything downstream can reference an application name. Once enabled it builds a local application signature database and an application system cache; the cache is what keeps per-session classification cheap, so leave it enabled unless you are debugging identification accuracy.

set services application-identification
show services application-identification status
show services application-identification application-summary

Stage 2 — Add AppTrack to an Existing Policy

The lowest-risk first step is to attach AppTrack to a permissive rule and watch the logs. Nothing is blocked; you simply learn what actually crosses the firewall.

set security policies from-zone trust to-zone untrust policy P1 match source-address any
set security policies from-zone trust to-zone untrust policy P1 match destination-address any
set security policies from-zone trust to-zone untrust policy P1 match application any
set security policies from-zone trust to-zone untrust policy P1 then permit
set security policies from-zone trust to-zone untrust policy P1 then application-services application-tracking

Stage 3 — UTM Profiles and Unified Policies

A UTM policy is a bundle that maps each protocol to a scanning profile. The SRX lets you apply one profile to all protocols (HTTP, FTP, IMAP, SMTP, POP3) or assign them individually — which matters because FTP upload and download are separate directions and an SMTP antispam profile has nothing to do with HTTP web filtering.

# UTM policy referencing per-protocol profiles
set security utm utm-policy UTM-POLICY anti-virus http-profile AV-HTTP
set security utm utm-policy UTM-POLICY anti-virus ftp upload-profile AV-FTP-UP
set security utm utm-policy UTM-POLICY anti-virus ftp download-profile AV-FTP-DOWN
set security utm utm-policy UTM-POLICY web-filtering http-profile WF-HTTP
set security utm utm-policy UTM-POLICY content-filtering http-profile CF-HTTP

# Attach it to the policy that used to be port-only
set security policies from-zone trust to-zone untrust policy P1 then permit application-services utm-policy UTM-POLICY

Stage 4 — Enforce on Application Identity

Only now is it worth replacing application any with a named application. Because unified policies can match on AppID output, the rule below allows the business application regardless of which port it decides to use, which is the behaviour port-based rules can never deliver.

set security policies from-zone trust to-zone untrust policy P1 match application junos:HTTP
set security policies from-zone trust to-zone untrust policy P1 match application junos:SSH
set security policies from-zone trust to-zone untrust policy P1 match application my-custom-app

Start by denying one or two clearly unacceptable applications and watching the AppTrack log. A wholesale switch from any to a named-application allow-list on day one is how change windows get extended.

Verification

show security application-firewall rule-sets
show security utm session
show security flow session application | match "junos:"
show log messages | match APPID

If an application never appears in the AppTrack output, confirm AppID is licensed and enabled, then check whether the session is being decrypted — most modern applications are only identifiable inside TLS, which is what SSL proxy exists for.

Related on this site: SRX设备升级步骤 and our Junos Firewall Filters on EX: Port, VLAN and L3 Filters for stateless control-plane filters, and Junos SRX Flow Session Debugging: Commands in Order for tracing why a permitted session still drops.

原文链接:https://www.juniper.net/documentation/us/en/software/junos/application-identification/application-identification.pdf