84
J
N
S
UNIPER
ET
CREEN
Configuring STRM
to Collect IDP
Events
Configuring Juniper
NSM Protocol
Step 1
Step 2
Configuring STRM to
Collect Syslog from
an IDP Device
IDP
For example:
[syslog@juniper.net dayId="20061012" recordId="0"
timeRecv="2006/10/12 21:52:21" timeGen="2006/10/12 21:52:21"
domain="" devDomVer2="0" device_ip="10.209.83.4"
cat="Predefined" attack="TROJAN:SUBSEVEN:SCAN" srcZn="NULL"
srcIntf="NULL" srcAddr="192.168.170.20" srcPort="63396"
natSrcAddr="NULL" natSrcPort="0" dstZn="NULL" dstIntf="NULL"
dstAddr="192.168.170.10" dstPort="27374" natDstAddr="NULL"
natDstPort="0" protocol="TCP" ruleDomain="" ruleVer="5"
policy="Policy2" rulebase="IDS" ruleNo="4" action="NONE"
severity="LOW" alert="no" elaspedTime="0" inbytes="0"
outbytes="0" totBytes="0" inPak="0" outPak="0" totPak="0"
repCount="0" packetData="no" varEnum="31"
misc="<017>'interface=eth2" user="NULL" app="NULL" uri="NULL"]
Juniper NSM is a central management server for Juniper IDP. You can configure
STRM to collect and represent the Juniper IDP alerts as coming from a central
NSM, or STRM can collect syslog from the individual Juniper IDP device.
To configure STRM to Collect IDP events, you must:
•
Configuring Juniper NSM Protocol
Configuring STRM to Collect Syslog from an IDP Device
•
To configure STRM to integrate with a Juniper NSM device:
Configure the Juniper NSM protocol in the STRM interface.
To configure STRM to receive events from a Juniper NSM device using Juniper
NSM protocol, you must select the JuniperNSM option from the Protocol
drop-down list box when configuring your protocol configuration. For more
information, see Configuring Protocols in the Managing Sensor Devices Guide.
Configure the sensor device within the STRM interface.
To configure STRM to receive events from a Juniper NSM device, select the
Juniper Networks NetScreen-Security Manager (NSM) option from the Sensor
Device Type drop-down list box.
To configure STRM to receive events from a NetScreen IDP device, select the
Juniper Networks Intrusion Detection and Prevention (IDP) option from the
Sensor Device Type drop-down list box.
For more information on configuring devices, see the Managing Sensor Devices
Guide.
For more information regarding NetScreen IDP, see your NetScreen-Security
Manager documentation.
Configuring DSMs Guide