QRコードを使用して、グリーンフィールドSRXシリーズファイアウォールを Juniper Security Directorクラウド にオンボーディング

このトピックでは、QRコードを使用して、新しいクラウド対応ジュニパーネットワークスSRXシリーズ®ファイアウォールを Juniper Security Director Cloud にオンボーディングする手順を説明します。

SRXシリーズファイアウォールを Juniper Security Directorクラウドにオンボーディングするには、まずデバイスがクラウド対応か非クラウド対応かを確認することが重要です。

  • クラウド対応のSRXシリーズファイアウォールには、シャーシにQRまたはクレームコードが記載されており、 Juniper Security Director Cloudに迅速にオンボーディングできます。クラウド対応のSRXシリーズファイアウォールは、高度なセキュリティサービス、シームレスな統合、クラウド導入時の保護を提供します。携帯電話を使用して、QRコードをスキャンし、ポータルのガイド付き手順に従って、クラウド対応のSRXシリーズファイアウォールをオンボーディングできます。

  • クラウド対応ではないSRXシリーズファイアウォールにはQRコードやクレームコードがなく、手動でオンボーディングする必要があります。CLIコマンドまたはゼロタッチプロビジョニング(ZTP)を使用して、クラウド対応ではないSRXシリーズファイアウォールをオンボーディングできます。

サポートされているクラウド対応および非クラウド対応のSRXシリーズファイアウォールについては、 クラウドがサポートするファイアウォールJuniper Security Directorを参照してください。

始める前に

ラックをインストールし、クラウド対応のSRXシリーズファイアウォールの電源を入れます。デバイス固有の手順については、該当するハードウェアガイドを参照してください。

DHCPは、工場出荷時のデフォルト設定で、クラウド対応のSRXシリーズファイアウォール上のすべてのインターフェイスで有効になっています。いずれかのインターフェイスを使用してインターネットに接続できることを確認します。

ワークフロー

図1:グリーンフィールド導入Flowchart titled Greenfield Onboarding outlining steps for setting up and managing Juniper Networks' Cloud-ready SRX Series Firewalls using Juniper Security Director Cloud. Steps include installing the firewall, deciding on subscriptions, creating an account, adding firewall via QR code, associating with Security Director Cloud, and starting management. Note indicates cloud-ready status with QR claim code on the firewall.におけるクラウドへのJuniper Security Director SRXシリーズファイアウォールのオンボーディング

SRXシリーズファイアウォールをJuniper Security Director Cloudにオンボーディングします

  1. 必要な Juniper Security Director Cloudサブスクリプション を決定します。サブスクリプションのご購入については、営業担当者またはアカウントマネージャーにお問い合わせください。ポータルでデフォルトで利用可能な 30 日間のトライアル サブスクリプションを使用することもできます。
  2. https://sdcloud.juniperclouds.net/ に移動し、組織アカウントを作成をクリックします。

    画面の指示に従ってアカウントをアクティブ化します。アカウントの承認には最大7営業日かかります。

  3. Juniper Security Director Cloudポータルにログインし、サブスクリプションを追加をクリックし、詳細を入力してOKをクリックします。Juniper Security Director Cloud interface showing Add Subscriptions pop-up in Subscriptions section under Administration menu with navigation options on the left.

    追加したサブスクリプションを 管理 > サブスクリプションから表示します。サブスクリプションが表示されない場合は、 管理 > ジョブ ページに移動してステータスを表示します。

  4. 携帯電話を使用して、クラウド対応のSRXシリーズファイアウォール上のQRコードをスキャンします。表示されたリンクをクリックし、 SDクラウドへのクレーム を選択して Juniper Security Directorクラウド ログインページに移動します。Juniper Networks device registration interface with serial AA1111AA1111, model SRXxxxx, MAC address XX1111XX1111, and buttons for claiming to Mist or SD Cloud.
  5. 前提条件を読み、電子メールアドレスを入力し、 次へをクリックします。Login screen for Juniper Security Director Cloud. Enter email to proceed. Click Next to continue. View Prerequisites for device setup and account creation at sdcloud.juniperclouds.net.
  6. 画面の指示に従ってサインインします。Login page for Juniper Security Director Cloud with username, password fields, SSO, Juniper.net sign-in options, and a back link.
  7. デバイスを追加する組織を選択し、rootパスワードを入力し、デバイスの追加をクリックしますJuniper Security Director Cloud interface showing fields for organization, email userjuniper.net, device serial AA1111AA1111, model SRXxxxx, root password option, and Add Device button.

    おめでとうございます!デバイスが組織に正常に登録され、デバイスが Juniper Security Director Cloud に追加されました。携帯電話のページからログアウトします。Device registration confirmation for organization DEMO; next steps: power on device, log in to Juniper Security Director Cloud portal to manage. Logout button available.

  8. クラウド対応のSRXシリーズファイアウォールの電源を入れ、ラップトップまたはデスクトップを使用して Juniper Security Director Cloud ポータルにログインします。

    デバイス>インベントリページで新しく追加されたデバイスを表示します。

    Device management interface showing three devices: DEMO-AA1111AA1111, DEMO-TEST01, and srx1111111111111. Lists host name, device group, inventory status, device config status, management status, device health, subscriptions, OS version, and product model. Options for security logs configuration and manage subscriptions are available.
    注:

    デバイスの検出が完了するまでに数秒かかります。デバイス検出に成功すると、以下のステータス更新が表示されます。

    • インベントリステータス: 同期中

    • デバイス構成ステータス: 同期中

    • 管理ステータス: アップ

    おめでとうございます!これで、クラウド対応のSRXシリーズファイアウォールが正常にオンボーディングされました。これで、デバイスを Juniper Security Director Cloud サブスクリプションに関連付ける準備ができました。

SRXシリーズファイアウォールを Juniper Security Directorクラウド サブスクリプションに関連付ける

  1. [Inventory > Devices]に移動し、デバイスを選択して、[Manage Subscriptions]をクリックします。画面の指示に従います。Manage Subscriptions interface: 1 device selected; selected subscription 10Devices S-SD-1-C-1; 1 of 10 devices in use; expires 08 Nov 2027; Add Subscriptions link; Cancel and OK buttons.
  2. サブスクリプション 列 にデバイスのサブスクリプション名が表示されていることを確認します。 Devices management interface showing a table with columns: Host Name, Device Group, Inventory Status, Device Config Status, Management Status, Device Health, Subscriptions, OS Version, Product. Key device statuses: DEMO-AA1111AA1111 is In Sync, Up, No data for health. DEMO-TEST01 and srx111111111111 have Discovery Not Initiated, No Subscription. Buttons for Security Logs Configuration, Manage Subscriptions, and a More dropdown for additional options.

    おめでとうございます!デバイスが Juniper Security Directorクラウドに正常に関連付けられました。

Juniper Security Directorクラウドの機能を確認する

Juniper Security Direct Cloudのセットアップが開始されたので、ビジネスニーズを満たすJuniper Security Director Cloudの他の機能もご確認ください。特に役立つと思われる機能をいくつか紹介します。

表1:Juniper Security Director Cloudの機能
必要に応じて 次に

セキュリティポリシーを作成またはインポートし、セキュリティポリシーにルールを追加し、デバイスにセキュリティポリシーを展開します

セキュリティポリシーの概要を参照してください

コンテンツセキュリティプロファイルを設定して、複数のセキュリティ脅威タイプからネットワークを保護します

コンテンツセキュリティプロファイルの概要を参照してください

ATPクラウドを設定して、進化するセキュリティ脅威からネットワーク内のすべてのホストを保護

ファイル検査プロファイルの概要を参照してください

見つかったウイルス、ダウンしているインターフェイス、攻撃数、CPUの急増、システム再起動、セッションなど、トラフィックログとネットワークイベントを表示します

セッションの概要とすべてのセキュリティイベントの概要を参照してください