Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

Security policy firewall authentication now provides user identities for user role firewall provisioning

More Information:

Security policy firewall authentication now provides user identities for user role firewall provisioning

User identity information, maintained by firewall authentication, can also be mapped to the user's IP address and used for user role firewall enforcement. A new UIT, the firewall authentication table, provides firewall authentication data for username and role retrieval. When users authenticate to the firewall, usernames and roles (groups) are mapped to IP addresses and written to the firewall authentication table. The following command enables the firewall authentication table as an authentication source and specifies its priority among other available UITs: set security user-identification authentication-source firewall-authentication priority priority The firewall authentication table is propagated when a security policy permits firewall authentication and specifies the new type, user-firewall. Users are authenticated based on the access-profile configured for the policy. To trigger firewall authentication for HTTPS traffic, you also need to specify the SSL termination profile. This option is not needed for HTTP traffic. set security policies from-zone zone to-zone zone policy policy-name then permit firewall-authentication user-firewall access-profile profile-name ssl-termination-profile profile-name
Product / Application Software Introduced Release
SRX300 Junos OS 15.1X49-D35
SRX320 Junos OS 15.1X49-D35
SRX340 Junos OS 15.1X49-D35
SRX345 Junos OS 15.1X49-D35
SRX380 Junos OS 20.1R1
SRX550 Junos OS 12.1X45-D10
SRX550 HM Junos OS 15.1X49-D30
SRX2300 Junos OS 23.4R1
SRX4100 Junos OS 15.1X49-D65
SRX4120 Junos OS 25.2R1
SRX4200 Junos OS 15.1X49-D65
SRX4300 Junos OS 24.2R1
SRX4600 Junos OS 17.4R2
SRX4700 Junos OS 24.4R1-S2
SRX5400 Junos OS 12.1X46-D10
SRX5600 Junos OS 12.1X45-D10
SRX5800 Junos OS 12.1X45-D10