Junos
This document provides the steps required to configure the Junos Inspector.
Quick DetailsRecommended Agent: On-Premises
Supported Agents: On-Premises or Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: N/A
Parent/Child Type Inspector: No
Inspection via: SSH
Data Summary: Here
Inspector Setup Preparation
Configure Agent Access
Before starting with the Inspector setup, we will need to configure the Junos device such that a Liongard Agent can access it via SSH and log in with a valid username and password or SSH key.
- Create a Liongard Service Account with the required Junos permissions (see below) and either a password or SSH key that can be entered into Liongard for authentication purposes.
- Use (or set up) an On-Premises Agent inside the firewall (the recommended approach) or configure the firewall such that the SSH interface can be reached from your Self-Hosted Agent.
Required Junos permissions
The built-in read-only login class is not sufficient — it only grants the view permission, which excludes configuration data. The inspector also runs show configuration (in three formats) to collect device configuration, which requires the view-configuration permission as well.
Create a custom login class that includes both view and view-configuration, and assign your service account to it:
set system login class liongard-read-only permissions [ view view-configuration ]
set system login user <username> class liongard-read-only
commit
Replace <username> with the SSH username you'll enter in the Liongard inspector configuration. This account can then authenticate via SSH password or SSH key, per the existing configuration steps below.
Liongard Inspector Setup
In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the Junos Inspector > Select Add System.
Fill in the following information:
- Environment: Select the Environment this System Inspector should be associated to
- Friendly Name: Suggested "Junos [Environment Name]"
- Agent: Select the On-premises Agent installed for this Environment
- Inspector Version: Latest
- IP/Hostname: The IP address or hostname (resolvable from the Agent machine) of the Junos device.
- SSH Port: SSH port reachable from the Agent machine.
- SSH Username: Username on the Junos device for use by the Inspector.
- SSH Passwordor SSH Private Key: The password or SSH key associated with the above Username.
- SSH Passphrase for Private Key: (IF CONFIGURED) SSH key passphrase, if using a private key with a passphrase.
- Scheduling: The Inspector will default to run once a day at the time the Inspector is set up. Here you can adjust the schedule
Select Save. The Inspector will now be triggered to run within the minute.
Updated 19 days ago

