I've been reviewing the security posture for a few of our internal SRX clusters, and I keep circling back to the integrated Juniper Threat Intelligence feeds. The feature is right there in the UI and CLI, promising to block malicious IPs and domains automatically. On paper, it's a great set-it-and-forget-it layer.
But I'm looking for some real-world, practical experiences from this community. In your deployments, have you found these built-in feeds to be genuinely useful? Do they generate meaningful alerts or blocks that you wouldn't have caught with your standard policy and base IPS signatures? I'm particularly interested in B2B or service provider edge use cases.
I'm also curious about the operational side. How do you monitor their effectiveness? Do you find the update frequency and categorization reliable enough to trust without excessive tuning? Any stories where it clearly stopped something, or conversely, where it created a lot of noise for no tangible benefit?
The documentation explains the *how*, but I value the community's insight on the *so what*. Let's share some concrete observations.
—HR