Add Security Policy Rules to Secure Edge Policy

Migrate your on-premises SRX Series Firewall security policies to Secure Edge by converting the security policy rules to a Secure Edge policy.

  • Zones—Secure Edge policies supports a single pair of zones from the trust zone to the untrust zone.

    • The zones of the security policy in the source endpoints are converted to trust zone.

    • The zones in the destination endpoints are converted to untrust zone.

  • Global rules—Secure Edge converts global security policy rules only if the policy rules match with the selected source and destination zones to be converted.

  • Security profiles—Secure Edge converts advanced security profiles in the following manner:

    Table 1: Security Profile Conversion
    Security profile Conversion

    Decrypt profile

    The profiles are converted without modification, except for the root certificate.

    The root certificate set is converted to Secure Edge with the name jsec-ssl-proxy-root-cert. Each decrypt profile name is prefixed with jse-.

    Web filtering profile

    The profile is converted and a new Secure Edge Web Filtering profile is created with categories that map to the actions and default settings of the converted profile.

    SecIntel profile

    The profiles are converted without modification.

    The profile name is prefixed with jse-.

    Anti-malware profile

    The HTTP Anti-malware profile is converted without modification. The profile name is prefixed with jse-.

    The SMTP and IMAP Anti-malware profiles are ignored and not converted.

    IPS

    The policy is ignored and not converted.

    The default IPS policy of Secure Edge policy is associated with the converted Secure Edge policy. See IPS Profiles Overview.

    Content filtering

    The policy is ignored and not converted.

    The default Content filtering profile of Secure Edge policy is associated. See Content Filtering Profiles Overview.

    Antivirus profile

    The profile is ignored and not converted.

    Antispam profile

    The profile is ignored and not converted.

Secure Edge doesn't reconvert SRX Series Firewall security policy rules that have already been converted to a Secure Edge policy. However, if you add new rules to that SRX Series Firewall policy, you can convert and append the new policy rules to the existing Secure Edge policy.

Prerequisites

Before you begin, make sure that the source endpoint identities defined in your SRX Series Firewall security policy rules match the source endpoint identities configured in JIMS Secure Edge. This helps prevent configuration conflicts and avoids the need for additional customization.

To add the security policy rules to Secure Edge policy:

  1. Select Security > Security Policies.
    The Security Policies page is displayed.
  2. Select the security policy to convert and click More > Add SRX policy rules to Secure Edge policy.
    The Getting Started page is displayed.
    Figure 1: Getting Started Page User interface for adding SRX policy rules to Secure Edge policy. Progress bar shows step 1 of 3: Getting Started. Message: Rules from yhh will append to existing policy. Note: Some SRX Security Subscriptions replaced with default Secure Edge ones. Cancel and Next buttons at top right.
  3. Click Next.

    The Add Rule Options page is displayed.

  4. Complete the configuration as shown in Table 1.
    Table 2: Fields on the Add Rule Options Page
    Field Description

    Name

    The name of the SRX Series Firewall security policy.

    Source (trust) zones

    Select the source zones applicable for the Internet in the existing rules.

    These zones are set as source (trust) zones in the Secure Edge policy rule.

    Destination (untrust) zones

    Select the destination zones applicable for the Internet in the existing rules.

    These zones are set as destination (untrust) zones in the Secure Edge policy rule.

  5. Click Next.

    The Review Rules Page is displayed.

    Figure 2: Rules Preview Page User interface for adding SRX policy rules with a progress bar on 'Review Rules', a rules table detailing policy specifics, and navigation buttons 'Cancel', 'Back', and 'Finish'.
  6. Review the converted rules and click Finish.

    A confirmation message about the successful conversion of the SRX Series Firewall security policy rules to a Secure Edge policy is displayed.

  7. Click OK.

    The Secured Edge Policy page is displayed.

    The converted SRX Series Firewall security policy rules are appended at the bottom of the existing Secure Edge policies.

  8. Deploy the Secure Edge policy.