Example: Update Attack Objects And Push To Connected Devices; Scheduling The Update - Juniper NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide
298
Table 30: Scheduled Security Update (SSU) Command Line
Parameters (continued)
Parameter
Definition
--retry
Directs the server to update the device the next time it connects.
If the device has changed while offline, the server will take action
based on the next parameter.
Requires modified device parameter (abort or override).
--abort
Directs the server to abort the update attempt if the device has
changed while offline. The device configuration state is set to
"Both Changed", indicating that both the device and NSM have
pending changes.
--override
Directs the server to update the device with the new attack
objects, overwriting any out-of-band changes made to the
device.

Example: Update Attack Objects and Push to Connected Devices

To download a new attack database and push it to connected devices only (ignore
unconnected devices), use the following command line.
/usr/netscreen/GuiSvr/utils/guiSvrCli.sh --update-attacks --post-action
--update-devices --skip

Scheduling the Update

You can perform a one-time security update using
crontab (or another scheduling utility) to configure the update to run at the intervals you
desire.
NOTE: Before performing or scheduling a security update, we recommend
that you disable the autoupdate setting for all managed devices. To disable
this setting in the device configuration, from the device navigation tree, select
Security > Attack DB > Settings, then set the Schedule Mode to Disable
To perform a one-time security update:
Log in to the NSM GUI Server as root.
1.
Change to the utility directory by typing: cd /usr/netscreen/GuiSvr/utils.
2.
Type the following to update attacks, including specifying the post-action options for
3.
the update:
guiSvr.sh --update-attacks --post-action post-action options
Enter your domain/username and password when prompted.
4.
To configure a scheduled security update using crontab:
directly, or you can use
guiSvrCli.sh
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.4

Table of Contents