Introduction
Juniper ATP Cloud identifies compromised hosts on a network, assigns a threat level, and adds their IP addresses to an IH feed. SRX Series Firewalls consume this feed and block network access by enforcing configured SecIntel policies. ATP Cloud and SRX firewalls work together to form a layered security approach. ATP Cloud identifies infected hosts, and the SRX firewalls block or mitigate threats based on security policies. This layered approach is ideal for north-south traffic passing between internal hosts and external networks.
However, if a compromised or infected host attempts to send malicious traffic to other hosts inside the same data center, subnet, or zone (eat-west traffic), that traffic does not pass through an SRX firewall and policies are not enforced. Since the SRX doesn’t have visibility into the east-west traffic traversing the data center, it can potentially spread and infect other hosts. Apstrs ConnectorOps for Infected Host Isolation addresses this gap. It has access to the fabric topology learned from Apstra DC Director. It can independently poll ATP Cloud for IH intelligence, and correlate an infected host’s IP address to its connected switch interface. It automatically isolates the compromised host at the fabric edge by disabling its switch interface or applying an ACL that blocks traffic from its MAC address.