Skip to content
Notifications
Clear all

Migrated from Sophos UTM to Juniper SRX for a 100-user shop - what broke

32 Posts
31 Users
0 Reactions
2 Views
(@gregoryt)
Estimable Member
Joined: 2 weeks ago
Posts: 147
 

Oh man, that NAT thing tripped me up too when I was learning. So if I'm reading this right, on Sophos the firewall rule just allowed the traffic and NAT was bundled in? But with Juniper you have to let the NATed IP out in a separate rule? That's a big change.

What did you end up doing for web filtering? I'm looking at a similar move and the built-in proxy is a big thing to lose.

The logging sounds painful. Is it all going to syslog now?



   
ReplyQuote
(@bearclaw)
Estimable Member
Joined: 3 weeks ago
Posts: 186
 

Yes, NAT and policy are separate. It's not just a separate rule, it's a separate table. Your security policy evaluates the post-NAT traffic, not the original.

Web filtering? We ripped it out and went DNS-based. The SRX proxy isn't worth the CPU hit for 100 users.

Logs are syslog, but structured. It's a firehose. You filter it on the collector side, not the firewall. Trying to make the SRX sort it will melt the box.


Prove it.


   
ReplyQuote
Page 3 / 3