What problem does it solve? Juniper SRX policy work is unforgiving: a wrong rule order, a shadowed global policy, or a misattached UTM profile can silently break segmentation or inspection. This Skill pins the agent to verified Junos 23.x syntax and an enforced global-policy output contract so generated, migrated, and audited SRX policies are correct, ordered, and reviewable. ## Core Features & Use Cases - Global-Policy Generation and Migration: Converts zone-pair contexts and other vendors' rulebases into one ordered security policies global table with preserved rule order, global address-book objects, and Junos application sets. - Security Services Attachment: Guides AppID/AppFW, NextGen Web Filtering (NGWF), Enhanced Web Filtering (EWF), SecIntel, and ATP integration, including license, platform, and fallback verification. - Troubleshooting and Verification: Provides hit-count analysis, show security match-policies prediction, insert-ordering pitfall checks, and a symptom-to-fix matrix for shadowed rules and failed inspections. - Use Case: Migrating a FortiGate rulebase to an SRX345 on Junos 23.4R1 — the Skill normalizes objects into the global address book, emits an ordered global policy table with a logged default deny, and attaches NGWF to permitted web traffic. ## Quick Start Use the srx-policy skill to convert this zone-pair SRX configuration into an ordered global policy table with a logged default deny.