Course Overview
The two-day NSM for SRX course discusses the basic operations of Network and Security Manager as applied to the SRX product. Key topics include server and domain administration, device configuration, template creation and management, policy creation and management, logging, and report generation.
Through demonstrations and hands-on labs, students gain experience in configuring, testing, and troubleshooting features of the Juniper NSM, by the end of this course, students will be able to use Juniper Security Manager to manage SRX Firewall/VPN and routing products.
Course Topics
- Configure and monitor zones
- Configure and monitor security policies
- Configure and monitor firewall user authentication
- Configure and monitor options to prevent network attacks
- Implement and monitor NAT using JUNOS security
- Implement and monitor policy-based and route-based IPsec VPNs
- Utilize and update the IDP signature database on SRX platforms
- Configure and monitor IDP policy with policy templates
- Configure and monitor high availability chassis clusters
Target Audience
Network engineers, technical support personnel, reseller support engineers, and others responsible for implementing
and or maintaining the Juniper Networks products covered in this course.
Course Outline
Day 1
Chapter 1: Course Introduction
Chapter 2 – Adding Devices
- Identify various methods for adding devices to NSM
- Identify how to add IP Reachable devices to NSM
- Identify how to add IP Not Reachable device to NSM
- Explain the use of Model devices
Chapter 3 – Templates and Device Configuration
- Describe what a template is in NSM
- Creating Templates in NSM
- Applying Templates in NSM
- Basic configuration of an SRX device
Day 2
Chapter 4 – Address Objects and Security Policies
- Define an Address Object
- Define a Security Policy
- Identify how to use NSM’s Policy Manager to create and assign policies
Chapter 5 – Network Translation
- Configure Static Network Address Translation
- Configure Dynamic Destination Network Address Translation
- Configure Dynamic Source Network Address Translation
Chapter 6 – IPSEC VPNS
- Configure IKE Policies using NSM
- Configure IPSEC Policies using NSM
- Configure policy and route based VPN Tunnels
Chapter 7 – Enabling IDP
- Load the Detector Engine on a JUNOS device
- Configure and apply IDP
- Add an IDP License to a Juniper Device
This course is available as open-enrollment Classroom event, instructor-led Live Virtual Class, REAL-ILT™ or as part
of a custom Onsite Training for up to 16 students.
Prerequisites
Students should have basic networking knowledge and an understanding of the OSI model and the TCP/IP protocol suite.