Sample output:
root> show system license usage
Feature name
Licenses
usedLicenses
installedLicenses
neededExpiry
av_key_kaspersky_engine
1
0
1
29 days
anti_spam_key_sbl
1
0
1
29 days
wf_key_surfcontrol_cpa
1
0
1
29 days
ax411-wlan-ap
0
2
0
permanent
av_key_sophos_engine
1
0
1
29 days
logical-system
0
1
0
permanent
If the license is not installed, refer to KB14103 - SRX License Installation steps after registering product for auto license installation. You can also download the license file and add it by using the following command:
Configuration:root>request system license add terminal
The configuration is similar to that of the other AV engines.
JWeb procedure:
Configure the express antivirus feature profile:
- Go to Configure > Security > UTM > Global options and click the Anti-Virus tab.
- In the Engine Type list, select Sophos and click OK.
- If the policy is successfully saved, you will receive a confirmation; click OK again. If the profile is not successfully saved, you can click Details in the displayed pop-up window to find out the reason.
- Go to Configure > Security > Policy > UTM Policies and click Add to configure a UTM policy; the Add Policy window is displayed.
- In the Main tab, next to Policy Name, type a unique name for the UTM policy (for example, sophos-utm-policy).
- Click the Anti-Virus profiles tab.
- Next to the HTTP profile, select junos-sophos-av-defaults and click OK.
- If the policy is successfully saved, you will receive a confirmation; click OK again. If the profile is not successfully saved, you can click Details in the displayed pop-up window to find out the reason.
- Go to Configure > Security > Policy > FW Policies.
- From the Security Policy window, click Add to configure a security policy with UTM. The policy configuration window is displayed.
- In the Policy tab, type a name in the Policy Name text box.
- In Default Policy Action, select either Deny-All or Permit-All.
- In From Zone, select a zone from the list and in To Zone, select a zone from the list.
- Under Zone Direction, click Add a Policy.
- Select a Source Address.
- Select a Destination Address.
- Choose an application by selecting junos-protocol (for all protocols that support antivirus scanning) in the Application Sets list and clicking the right arrow key (—>) button to move it to the Matched box.
- In Policy Action, select Permit.
- Click the Application Services tab.
- In UTM Policy, select the appropriate policy from the list. This action attaches the UTM policy to the security policy.
- Click OK.
- If the policy is successfully saved, you will receive a confirmation; click OK again. If the profile is not successfully saved, you can click Details in the displayed window to find out the reason.
- Configuring the type of engine:
set security utm feature-profile anti-virus type sophos-engine
- Configure the UTM policies for the desired protocols:
set security utm utm-policy sophos-utm-policy anti-virus http-profile junos-sophos-av-defaults
set security utm utm-policy sophos -utm-policy anti-virus ftp upload-profile junos-sophos-av-defaults
set security utm utm-policy sophos -utm-policy anti-virus ftp download-profile junos-sophos-av-defaults
set security utm utm-policy sophos -utm-policy anti-virus smtp-profile junos-sophos-av-defaults - Apply this UTM policy in a security policy:
set security policies from-zone trust to-zone untrust policy utm-security-policy match source-address any
set security policies from-zone trust to-zone untrust policy utm-security-policy match destination-address any
set security policies from-zone trust to-zone untrust policy utm-security-policy match application any
set security policies from-zone trust to-zone untrust policy utm-security-policy then permit application-services utm-policy sophos-utm-policy
Troubleshooting:
- Check the status of the Sophos engine:
root> show security utm anti-virus status
utm anti-virus status:
anti-virus key expire date: 29 days left (grace period)
update server: http://update.juniper-updates.net/sav/
interval: 1440 minutes
pattern update status: next update in 1347 minutes
last result: download version file failed
anti-virus signature version: not loaded
scan engine type: sophos-engine
scan engine information: last action result: No error - Check the Sophos AV statistics:
root> show security utm anti-virus statistics
This comment has been removed by the author.
ReplyDeleteJuniper : Introduction To The Junos Operating System: Configure Sophos Anti-Virus On Srx Devices >>>>> Download Now
ReplyDelete>>>>> Download Full
Juniper : Introduction To The Junos Operating System: Configure Sophos Anti-Virus On Srx Devices >>>>> Download LINK
>>>>> Download Now
Juniper : Introduction To The Junos Operating System: Configure Sophos Anti-Virus On Srx Devices >>>>> Download Full
>>>>> Download LINK lk
The information which you have provided in this blog is really useful to everyone. Thanks for sharing.
ReplyDeleteSophos Support
Sophos Security Services
Thank you for sharing this useful information. Do you know Antivirus is really necessary if you want to keep your Computer, laptop, phone, or another electronic device that comes enabled with webcams are safe. If you want to know about antivirus follow our blog, and here is our latest blog:- What is Virus Signature.
ReplyDeleteThank You for sharing this wonderful and much required information in this post.
ReplyDeleteSophos Security Service
Sophos Support