To enable Juniper NextGen Web Filtering, the SRX must have the required NGWF license and the web-filtering type must be configured for NGWF. Juniper documentation states that Enhanced Web Filtering and NGWF require separate licenses and that NGWF can use the wf_key_ng_juniper license key. Juniper also documents NGWF as a configurable web-filtering type, including ng-juniper, and notes that administrators can confirm missing license conditions using the web-filtering status command. A public IP address on the loopback interface is not a general NGWF requirement. SSL host inbound traffic on the untrust zone is also not required for enabling NGWF; SSL proxy or SNI behavior may affect HTTPS inspection, but it is not the base enablement step.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit