2 Commits

Author SHA1 Message Date
9b03b78da3 Add AI security improvements with feedback learning 2025-09-05 00:25:04 +00:00
c05ce2eb26 Initial commit 2025-09-04 21:38:13 +00:00
3 changed files with 11 additions and 38 deletions

2
README.md Normal file
View File

@@ -0,0 +1,2 @@
# SRX AI Configuration Repository
AI-generated network configurations for Juniper SRX

View File

@@ -1,38 +0,0 @@
# AI-Generated SRX Configuration
# Generated: 2025-09-05T03:46:59.387474
# Analysis Period: Last 7 days
{'config': 'set security address-book global address-set INTERNAL-NETS address 192.168.100.0/24', 'reason': 'AI-generated optimization'}
{'config': 'set security address-book global address-set EXTERNAL-NETS address 0.0.0.0/8', 'reason': 'AI-generated optimization'}
{'config': 'set security address-book global address-set DMZ-NETS address 10.0.0.0/8', 'reason': 'AI-generated optimization'}
{'config': 'set security screen ids-option WAN-screen icmp flood threshold 20', 'reason': 'AI-generated optimization'}
{'config': 'set security screen ids-option WAN-screen tcp syn-flood attack-threshold 20', 'reason': 'AI-generated optimization'}
{'config': 'set security screen ids-option WAN-screen udp-flood-protection threshold 20', 'reason': 'AI-generated optimization'}
{'config': 'set security address-book entry ANY-EXTERNAL to 0.0.0.0/0', 'reason': 'AI-generated optimization'}
{'config': 'set security address-book entry DISCORD-NET1 to 162.159.0.0/16', 'reason': 'AI-generated optimization'}
{'config': 'set security address-book entry GAMING-NETWORK to 192.168.10.0/24', 'reason': 'AI-generated optimization'}
{'config': 'set security logging session-init enable', 'reason': 'AI-generated optimization'}
{'config': 'set security logging session-close enable', 'reason': 'AI-generated optimization'}
{'config': 'set security idps-signature-set input-tag 1000', 'reason': 'AI-generated optimization'}
{'config': 'set security idps-signature-set output-tag 2000', 'reason': 'AI-generated optimization'}
{'config': 'set security application-control rule WAN-rule permit any', 'reason': 'AI-generated optimization'}
{'config': 'set security application-control rule HOME-rule permit any', 'reason': 'AI-generated optimization'}
{'config': 'set security application-control rule GUEST-rule permit any', 'reason': 'AI-generated optimization'}
{'config': 'set security application-control rule IOT-rule permit any', 'reason': 'AI-generated optimization'}
{'config': 'set security application-control rule ENTERTAINMENT-rule permit any', 'reason': 'AI-generated optimization'}
{'config': 'set security application-control rule MGMT-rule permit any', 'reason': 'AI-generated optimization'}
{'config': 'set security application-control rule INFRA-rule permit any', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule source-address WAN-rule any 1000/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule source-address HOME-rule any 500/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule source-address GUEST-rule any 300/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule source-address IOT-rule any 200/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule source-address ENTERTAINMENT-rule any 150/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule source-address MGMT-rule any 100/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule source-address INFRA-rule any 50/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule destination-address WAN-rule any 1000/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule destination-address HOME-rule any 500/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule destination-address GUEST-rule any 300/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule destination-address IOT-rule any 200/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule destination-address ENTERTAINMENT-rule any 150/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule destination-address MGMT-rule any 100/sec', 'reason': 'AI-generated optimization'}
{'config': 'set security rate-limiting rule destination-address INFRA-rule any 50/sec', 'reason': 'AI-generated optimization'}

9
ai_suggestions.conf Normal file
View File

@@ -0,0 +1,9 @@
# MANDATORY: Address-set definitions
set security address-book global address-set INTERNAL-NETS address 192.168.100.0/24
set security address-book global address-set EXTERNAL-NETS address 0.0.0.0/8
set security address-book global address-set DMZ-NETS address 10.0.0.0/8
# DDoS Protection - Fixed thresholds (no XML!)
set security screen ids-option WAN-screen icmp flood threshold 20
set security screen ids-option WAN-screen tcp syn-flood attack-threshold 20
set security zones security-zone WAN screen WAN-screen