Juniper Advanced Threat Prevention Appliance
22
Copyright© 2018, Juniper Networks, Inc.
set honeypot (collector mode)
set traffic-monitoring (for JATP700 Appliances only) (collector mode)
Table 2-17 set honeypot
Description
Enables and disables the SSH-Honeypot feature for a Traffic Collector.
A honeypot can be deployed within a customer network to detect network activity
generated by malware attempting to infect or attack other machines in a local area
network. These attempted SSH logins can be used to supplement detection of
lateral spread.
There are two parameters that can be set for a honeypot:
• Enable/disable a honeypot
• Set a Static IP (IP, mask, and gateway) or DHCP of a publicly addressable inter-
face
See Also:
show honeypot
command in
Product(s) CLI
All-in-One | Collector
Mode(s)
collector
Syntax
(collector)# set honeypot ssh-honeypot enable dhcp
(collector)# set honeypot ssh-honeypot enable address (IP
address) netmask (subnet IP) gateway (IP address)
(collector):# set honeypot ssh-honeypot disable
Example
The following example enables the SMB parser for lateral detections:
(
collector)
#
set honeypot ssh-honeypot enable
address 1.2.3.4 netmask 255.255.0.0 gateway
1.2.3.1
NOTE
The static IP configuration does not require configuring DNS.
Honeypots do not require a DNS server at this time.
Table 2-18 set traffic-monitoring
Description
Sets the traffic monitoring interface on the JATP700
Product(s) CLI
All-in-One | Collector
Mode(s)
collector
Syntax
# set traffic-monitoring-ifc 1gb_ifc
Set the traffic monitoring interface to be the 1G interface.
# set traffic-monitoring-ifc 10gb_ifc
Set the traffic monitoring interface to be the 10G interface.
NOTE
After making an interface type change, the system must be rebooted
for the change to take effect.
Summary of Contents for Advanced Threat Prevention Appliance
Page 70: ...Juniper Advanced Threat Prevention Appliance 62 Copyright 2018 Juniper Networks Inc ...
Page 94: ...Juniper Advanced Threat Prevention Appliance 86 Copyright 2018 Juniper Networks Inc ...
Page 118: ...Juniper Advanced Threat Prevention Appliance 110 Copyright 2018 Juniper Networks Inc ...