Cloud Delivered Security with Juniper Secure Edge User Guide
- June 15, 2024
- JUNIPer
Table of Contents
- Cloud-Delivered Security with Juniper Secure Edge
- Product Information
- Product Usage Instructions
- IN THIS GUIDE
- Set Up Your Service Location
- Deploy Your Secure Edge Policy
- What’s Next?
- General Information
- Learn with Videos
- References
- Read User Manual Online (PDF format)
- Download This Manual (PDF format)
Cloud-Delivered Security with Juniper Secure Edge
Product Information
Specifications
- Product Name: Juniper Secure Edge
- Cloud-Delivered Security
Product Usage Instructions
Step 1: Begin
Set Up Your Service Location
-
Decide the Juniper Secure Edge Subscriptions you need and reach out to your sales representative or account manager to purchase the selected subscriptions.
-
Go to https://sdcloud.juniperclouds.net. and click “Create an organization account”.
-
Follow the on-screen instructions to activate your account. If you already have an organization account with Juniper Security Director Cloud, skip to Step 2.
-
Log in to the Juniper Security Director Cloud portal, click “Add Subscriptions”, enter details, and click “OK”.
-
Go to “Secure Edge > Service Administration > Certificate Management”, and click “Generate”.
- If your company maintains a Private Key Infrastructure (PKI) and Certificate Authority (CA), select “Certificate Signing Request (CSR)”. Enter the details, click “OK”, and download the CSR file. Get your CA’s signature on the certificate and upload the signed certificate.
- If your company does not have a CA, select “Juniper Issued Certificate”, enter details, and click “OK”. Download and distribute the certificate among your managed devices.
-
You must install the certificate in your browser’s trusted root store.
-
Go to “Secure Edge > Service Management > Service
Locations” and click the plus (+) sign.- Provide the service location details, link the Secure Edge subscriptions, and click “OK”.
Step 2: Up and Running
Set Up User Profiles
- Select “Secure Edge > Service Management > Sites” and click the plus (+) sign. Enter the site details, traffic forwarding information, site configuration, and click “Finish”.
- From the “Deploy Status > Tunnel configuration”, click “Copy to Clipboard”. Paste the configuration in the CLI of your customer premises equipment (CPE) device and commit the changes.
- Select “Secure Edge > Service Management > IPsec Profiles”, click the plus (+) sign, enter the required information, and click “OK”.
For Roaming Users
- Go to “Secure Edge > Identity > User Authentication” and select an authentication method (Security Assertion Markup Language (SAML), Lightweight Directory Access Protocol (LDAP), or Hosted Database). Enter the required configuration and click “Save”.
- Select “Secure Edge > Service Administration > PAC Files”. Select the proxy auto-configuration (PAC) file and click “Copy URL”.
- Go to your browser proxy settings, paste the URL of the PAC file, and click “Save”.
- Select “Secure Edge > Service Administration > Explicit Proxy Profiles”. Enter the port number of the proxy server and select the decrypt profile from the list. If you do not have a decrypt profile, click “Create Decrypt Profile”, enter the required information, and click “Save”.
Deploy Your Secure Edge Policy
Instructions for deploying the Secure Edge Policy are not provided in the text-extract.
FAQ
Q: How can I purchase Juniper Secure Edge Subscriptions?
- A: Contact your sales representative or account manager to purchase the selected subscriptions.
Q: How can I activate my Juniper Security Director Cloud account?
- A: Go to https://sdcloud.juniperclouds.net/, click “Create an organization account” and follow the on-screen instructions.
IN THIS GUIDE
- Step 1: Begin | 1
- Step 2: Up and Running | 4
- Step 3: Keep Going | 8
Step 1: Begin
- IN THIS SECTION
- Set Up Your Service Location | 1
- In this guide, we provide a simple, three-step path to quickly get you up and running with Juniper® Secure Edge. You’ll set up your service location, also known as point of presence (POP).
- Use the service location as an access point to configure and deploy secure edge policies for on-premises and roaming users.
Set Up Your Service Location
Decide the Juniper Secure Edge Subscriptions you need and reach out to your sales representative or account manager to purchase the selected subscriptions.
- Go to https://sdcloud.juniperclouds.net/ and click Create an organization account.
- Follow the on-screen instructions to activate your account. If you already have an organization account with Juniper Security Director Cloud, skip to Step 2.
- Log in to the Juniper Security Director Cloud portal, click Add Subscriptions, enter details, and click OK.
- Go to Secure Edge > Service Administration > Certificate Management, and click Generate.
- a. If your company maintains a Private Key Infrastructure (PKI) and Certificate Authority (CA), select Certificate Signing Request (CSR). Enter the details, click OK, and download the CSR file. Get your CA’s signature on the certificate and upload the signed certificate.
- b. If your company does not have a CA, select Juniper Issued Certificate, enter details, and click OK. Download and distribute the certificate among your managed devices.
- You must install the certificate in your browser’s trusted root store.
- Go to Secure Edge > Service Management > Service Locations and click the plus (+) sign. Provide the service location details, link the Secure Edge subscriptions, and click OK.
To continue onboarding, proceed to Step 2.
Step 2: Up and Running
IN THIS SECTION
- Set Up User Profiles | 5
- Deploy Your Secure Edge Policy | 8
- Now that you’ve set up your service location, you’re ready to configure and deploy Juniper Secure Edge policies for on-premises and roaming users.
Set Up User Profiles
For On-Premises Users
- Select Secure Edge > Service Management > Sites and click the plus (+) sign. Enter the site details, traffic forwarding information, site configuration and click Finish.
- From the Deploy Status > Tunnel configuration, click Copy to Clipboard. Paste the configuration in the CLI of your customer premises equipment (CPE) device and commit the changes.
- Select Secure Edge > Service Management > IPsec Profiles, click the plus (+) sign, enter the required information, and click OK.
For Roaming Users
- Go to Secure Edge > Identity > User Authentication, select an authentication method (Security Assertion Markup Language (SAML), Lightweight Directory Access Protocol (LDAP), or Hosted Database), enter the required configuration, and click Save.
- Select Secure Edge > Service Administration > PAC Files. Select the proxy auto-configuration (PAC) file and click Copy URL.
- Go to your browser proxy settings, paste the URL of the PAC file, and click Save.
- Select Secure Edge > Service Administration > Explicit Proxy Profiles. Enter the port number of the proxy server and select the decrypt profile from the list. If you do not have a decrypt profile, click Create Decrypt Profile, enter the required information, and click Save.
Deploy Your Secure Edge Policy
- Select Secure Edge > Security Policies and click the plus (+) sign to create a new rule.
- Enter the required information, click ✓ to save the policy, and click Deploy. For on-premise users, the site tunnel status displays as in the portal. For roaming users, the end user authentication status displays as Success.
- Congratulations! You have successfully onboarded Juniper Secure Edge for on-premises and roaming users!
Step 3: Keep Going
- IN THIS SECTION
- What’s Next? | 9
- General Information | 9
- Learn with Videos | 9
What’s Next?
Use the Juniper Security Director Cloud portal to configure and monitor Secure Edge services for your network. Here are some things you can do next:
If You Want To | Then |
---|---|
Configure allowlists and blocklists to filter trusted and untrusted resources |
See Create Allowlists and
Blocklists
Configure anti-malware profiles to inspect malware| See Create Anti-malware
Profile
Configure content filtering policies to prevent access to malicious content|
See Create a Content Filtering
Policy
Configure Secure Edge policy rule to specify actions for a transit traffic|
See Add a Secure Edge Policy
Rule
General Information
If You Want To | Then |
---|---|
See all the available documentation for Juniper Secure Edge | Visit [Juniper |
Secure Edge](https://www.juniper.net/documentation/product/us/en/juniper-
secure-edge/)
See all the available documentation for Juniper Security Director Cloud| Visit
Juniper Security Director
Cloud
Learn with Videos
If You Want To | Then |
---|---|
Understand what is Secure Access Service Edge (SASE) | Watch [What is |
SASE?](https://www.youtube.com/watch?v=RnGwiCGC08c)
Understand what is Juniper Secure Edge| Watch What is Juniper Secure
Edge?
See a demonstration of how to get started with Juniper Secure Edge| Watch
Getting Started with Juniper Secure
Edge
If You Want To| Then
---|---
Deploy Juniper Security Service Edge| See Juniper Secure Edge Training
Course
Learn how to manage security with Security Director Cloud and Juniper Secure
Edge| Watch Manage Security Anywhere With Security
Director Cloud and Juniper
Secure Edge
- Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. in the United States and other countries.
- All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document.
- Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.
- Copyright © 2023 Juniper Networks, Inc. All rights reserved.
References
- Deploying Juniper Security Service Edge
- Juniper Secure Edge Documentation | Juniper Networks
- Create Anti-malware Profile | SD Cloud | Juniper Networks
- Create a Content Filtering Policy | SD Cloud | Juniper Networks
- Add a Secure Edge Policy Rule | SD Cloud | Juniper Networks
Read User Manual Online (PDF format)
Read User Manual Online (PDF format) >>