Sign inSign up

lumutools/juniper-srx-threat-feeder

By lumutools

•Updated about 4 years ago

Juniper SRX Firewall Threat Feeder

Image
0

865

lumutools/juniper-srx-threat-feeder repository overview

⁠Lumu - Juniper SRX Firewall Integration

Lumu Defender offers a framework to help you leverage Lumu's integrations with your existing cybersecurity stack, including Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); Endpoint Detection and Response (EDR); incident response systems; and more.

The Lumu Defender Juniper SRX Firewall Out-of-the-box integration allows you to configure Juniper SRX Firewall to receive and block adversaries detected by Lumu and improve the detection & response capabilities of your organization; however, this type of integration is limited to deployments managed through the Juniper Security Director (Cloud or on-premise) with the Policy Enforcer component.

See more at: Lumu docs⁠

This repository provides you with the ability to integrate your Juniper SRX Firewalls with Lumu in the absence of the Juniper Policy Enforcer.

⁠Getting Started

This guide shows you how to use this project to feed your Juniper SRX Firewall with Lumu's confirmed compromises.

A dockerized version of this project is also available at LumuTools in DockerHub⁠

⁠Requirements

Before trying to run this project, be sure to properly set up the Lumu Defender Juniper SRX Firewall Out-of-the-box integration.
See more at: Lumu docs⁠

In order to run this project you'll need docker installed in the machine you intend to use it at.

⁠Usage
  1. Prepare the container (replace VALUE with proper values):
 docker create \
 -e INTEGRATION_UUID=VALUE \
 -e HOST_URL=VALUE \
 -e USERNAME=VALUE \
 -e PASSWORD=VALUE \
 -e FREQUENCY=VALUE \
 --restart unless-stopped \
 --name lumu-juniper-srx-threat-feeder \
 --log-opt tag=lumu-juniper-srx-threat-feeder \
 --log-opt max-size=100m \
 --log-opt max-file=1 \
 lumutools/juniper-srx-threat-feeder:latest
  1. Run it:
docker start lumu-juniper-srx-threat-feeder
⁠Parameters
  • INTEGRATION_UUID - Lumu integration uuid
  • HOST_URL - Juniper SRX Firewall URL
  • USERNAME - Username to login in Juniper
  • PASSWORD - Password to login in Juniper
  • FREQUENCY - Polling frequency in minutes (1-30). How often to check for updates.
⁠General Recommendations

For the proper functioning of the integration, follow these recommendations:

  • Integration between Lumu and your firewall is carried out using Webfilters, Categories and URL Pattern Lists named as follows:
    • Webfilter: lumu-detections
    • Categories: lumu-category-n where n is a number
    • Url-Pattern-List: lumu-blacklist-n where n is a number
  • Each of these objects is actively used and updated by this integration; therefore, they must not be modified.
  • Additional threats must not be added to elements created by this integration. Create or use other elements instead.
  • When using the Docker image, do not stop the container. This will cause the synchronization process to restart from scratch.
  • When using the Docker image, a frequency between 20 to 30 minutes is recommended.

⁠Find more about us

Tag summary

Content type

Image

Digest

sha256:ccb0691b7…

Size

21 MB

Last updated

about 4 years ago

docker pull lumutools/juniper-srx-threat-feeder