Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.107
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Configuration Notes")}}

Configuration Notes

{{ $t('productDocDetail.updateTime') }}: 2026-04-29

Configuration Item (Athena NGFW)

Description

ID Type

- The Juniper firewall supports only the following ID types: IPv4 address and FQDN.

Traffic of Interest

- This is supported only in route mode.

- By default, IPv4 is enabled. This is equivalent to a case in which the local/peer IPv4 address is set to all zeros. We recommend that you leave the proxy ID in the IKE settings of the Juniper firewall empty, or configure a single all-zero IPv4 address.

- IPv6 is enabled. This is equivalent to a case in which the local/peer IPv6 address is set to all zeros. We recommend that you leave the proxy ID in the IKE settings for the peer firewall empty, or configure a single all-zero IPv6 address.

Peer Tunnel Interface

- This is supported only in route mode.

- If the referenced VPN tunnel interface is not shared with other IPsec VPN tunnels, we recommend that you leave this configuration item empty.

- You must enter the address of the peer tunnel interface if OSPF or BGP is used.

- When you need to specify the next hop for the static route or policy route, make sure that the next hop address is the same as the peer tunnel interface address of the IPsec VPN tunnel. Otherwise, business traffic may fail to be routed.

Encrypted Traffic

- This is equivalent to the proxy ID in the IKE settings of Juniper. The local and peer IP addresses in the encrypted traffic can be customized only in policy mode. You cannot customize the local and peer IP addresses in route mode. In addition, only two encrypted traffic entries are predefined: one using an all-0 IPv4 address and the other using an all-0 IPv6 address. By default, IPv4 is enabled, and the traffic to be actually encrypted is determined by the address specified in the traffic of interest.

- In policy mode, multiple local/peer IP addresses can be configured in the encrypted traffic. To be specific, a maximum of 16 * 16 addresses can be configured.

- In policy mode, if multiple local/peer IP addresses are configured in the encrypted traffic on the Athena NGFW firewall, we recommend that you configure multiple proxy IDs in the IKE settings of the Juniper firewall.