Juniper SRX Firewall
You can integrate a Juniper SRX firewall with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Juniper SRX product overview
Juniper Networks SRX Series is a line of next-generation firewalls (services gateways) powered by Junos OS that deliver firewall, intrusion prevention, application awareness, content inspection, unified threat management (antivirus, anti-spam, URL filtering), and VPN in a single platform.
What we ingest
Sophos XDR collects Juniper SRX syslog data by listening for messages your firewall forwards to a Sophos XDR data collector. The following log categories are collected:
- Intrusion detections: IDP and IDS intrusion and screen detections raised by the firewall.
- Web filtering: UTM web-filtering URL activity.
- Authentication: Administrative and web authentication events.
- Firewall traffic1: Session create, close, and deny events.
Event and data types
We ingest the following event and data types from Juniper SRX:
- Intrusion detections: IDP and IDS signature and screen-based intrusion detections, with the attack, action, and source and destination endpoints. Normalized to network intrusion detection telemetry.
- Web filtering: UTM web-filter URL decisions, including the URL and action. Normalized to HTTP telemetry.
- Authentication: Administrative and web authentication events, including login and failure activity, with user and result. Normalized to authentication telemetry.
- Firewall traffic1: Session create, close, and deny decisions, including source and destination addresses and ports. Normalized to netflow telemetry.
Data provided by this integration
Data provided by Juniper SRX gets normalized to the following schemas:
authhttpnetflow1nids
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
-
Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview. ↩↩↩