MIB Viewer

JUNIPER-JS-SCREENING-MIB

90 objects
This module defines the MIB for Juniper Enterprise Firewall screen functionality. Juniper documentation is recommended as the reference. Juniper Security Firewall provides various detection methods and defense mechanisms to combat exploits at all stages of the path of execution. These includes: Setting screen options Firwall DOS attacks Network DOS attack OS specific DOS attack Fragment reassembly
Imported Objects
IF-MIBifName
JUNIPER-JS-SMIjnxJsScreening
SNMPv2-SMICounter64 Integer32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE
SNMPv2-TCDisplayString
OIDNameAccessStatusDescription
1.3.6.1.4.1.2636.3.39.1.8.1IdentityjnxJsScreenMIBThis module defines the MIB for Juniper Enterprise Firewall screen functionality. Juniper documentation is recommended as the reference. Juniper Security Firew…
1.3.6.1.4.1.2636.3.39.1.8.1.0NodejnxJsScreenNotifications
1.3.6.1.4.1.2636.3.39.1.8.1.0.1NotificationjnxJsScreenAttackcurrentA per min bytes exceed trap signifies that the number of bytes per minutes has exceeds the specified threshold. jnxJsScreenZoneName: the zone name under which …
1.3.6.1.4.1.2636.3.39.1.8.1.0.2NotificationjnxJsScreenCfgChangecurrentThe screening configuration change trap signifies that an screening option has been changed(enabled or disabled). A disable feature may implies a security hole…
1.3.6.1.4.1.2636.3.39.1.8.1.1NodejnxJsScreenObjects
1.3.6.1.4.1.2636.3.39.1.8.1.1.1TablejnxJsScreenMonTablenot-accessiblecurrentJuniper security Firewall can allow DI protection on each of the device's physical interface. This table collects the screen attributes that monitor the variou…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1RowjnxJsScreenMonEntrynot-accessiblecurrentThe screen option monitoring statistics entry. Each entry is uniquely identified by the zone name. The data is collected on a per zone basis. There can be mult…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.1ColumnjnxJsScreenZoneNameaccessible-for-notifycurrentThe name of the security zone under which the statistics are collected.
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.2ColumnjnxJsScreenNumOfIfread-onlycurrentNumber of interfaces bound to this zone. Each counter contains the aggregated data of all the interfaces
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.3ColumnjnxJsScreenMonSynAttkread-onlycurrentThe SYN (TCP connection request) attack is a common denial of service (DoS) technique characterized by the following pattern: - Using a spoofed IP address not …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.4ColumnjnxJsScreenMonTearDropread-onlycurrentTeardrop attacks exploit the reassembly of fragmented IP packets. In the IP header, one of the fields is the fragment offset field, which indicates one of the …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.5ColumnjnxJsScreenMonSrcRouteread-onlycurrentIP source route options can be used to hide their true address and access restricted areas of a network by specifying a different path. The security device sho…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.6ColumnjnxJsScreenMonPingDeathread-onlycurrentThe maximum allowable IP packet size is 65,535 bytes, including the packet header (typically 20 bytes long). An ICMP echo request is an IP packet with a pseudo…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.7ColumnjnxJsScreenMonAddrSpoofread-onlycurrentOne method to gain access to a restricted network is to insert a bogus source address in the packet header to make the packet appear to come from a trusted sou…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.8ColumnjnxJsScreenMonLandread-onlycurrentA combined SYN attack with IP spoof is referred to as Land attack. A Land attack occurs when an attacker sends spoofed SYN packets containing the IP address of…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.9ColumnjnxJsScreenMonIcmpFloodread-onlycurrentAn ICMP flood typically occurs when ICMP echo requests overload its victim with so many requests that it expends all its resources responding until it can no l…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.10ColumnjnxJsScreenMonUdpFloodread-onlycurrentUDP flooding occurs when an attacker sends IP packets containing UDP datagrams with the purpose of slowing down the victim to the point that it can no longer h…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.11ColumnjnxJsScreenMonWinnukeread-onlycurrentWinNuke is a DoS attack targeting any computer on the internet running Windows. The attacker sends a TCP segment, usually to NetBIOS port 139 with the urgent (…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.12ColumnjnxJsScreenMonPortScanread-onlycurrentA port scan occurs when one source IP address sends IP packets containing TCP SYN segments to a defined number of different ports at the same destination IP ad…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.13ColumnjnxJsScreenMonIpSweepread-onlycurrentAn address sweep occurs when one source IP address sends a defined number of ICMP packets to different hosts within a defined interval. The purpose of this att…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.14ColumnjnxJsScreenMonSynFragread-onlycurrentIP encapsulates a TCP SYN segment in the IP packet that initiates a TCP connection. The purpose is to initiate a connection and to invoke a SYN/ACK segment res…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.15ColumnjnxJsScreenMonTcpNoFlagread-onlycurrentA normal TCP segment header has at least one flag control set. A TCP segment with no control flags set is an anomalous event. Operating systems respond to such…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.16ColumnjnxJsScreenMonIpUnknownProtread-onlycurrentAccording to RFC 1700, some protocol types in IP header are reserved and unassigned at this time. Precisely because these protocols are undefined, there is no …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.17ColumnjnxJsScreenMonIpOptBadread-onlycurrentIP protocol specifies a set of eight options that provide special routing controls, diagnostic tools, and security. These eight options can be used for malicio…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.18ColumnjnxJsScreenMonIpOptRecRtread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.19ColumnjnxJsScreenMonIpOptTimestampread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.20ColumnjnxJsScreenMonIpOptSecurityread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.21ColumnjnxJsScreenMonIpOptLSRread-onlycurrentAttackers can use IP source route options to hide their true address and access restricted areas of a network by specifying a different path. The security devi…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.22ColumnjnxJsScreenMonIpOptSSRread-onlycurrentAttackers can use IP source route options to hide their true address and access restricted areas of a network by specifying a different path. The security devi…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.23ColumnjnxJsScreenMonIpOptStreamread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.24ColumnjnxJsScreenMonIcmpFragread-onlycurrentICMP provides error reporting and network probe capabilities. ICMP packets contain very short messages, there is no legitimate reason for ICMP packets to be fr…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.25ColumnjnxJsScreenMonIcmpLargeread-onlycurrentICMP packets contain very short messages, there is no legitimate reason for ICMP packets to be fragmented. If an ICMP packet is unusually large, something is w…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.26ColumnjnxJsScreenMonTcpSynFinread-onlycurrentBoth the SYN and FIN control flags are not normally set in the same TCP segment header. The SYN flag synchronizes sequence numbers to initiate a TCP connection…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.27ColumnjnxJsScreenMonTcpFinNoAckread-onlycurrentA FIN scan sends TCP segments with the FIN flag set in an attempt to provoke a response and thereby discover an active host or an active port on a host. The us…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.28ColumnjnxJsScreenMonLimitSessSrcread-onlycurrentAll the virus-generated traffic originates from the same IP address (generally from a infected server), a source-based session limit ensures that the firewall …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.29ColumnjnxJsScreenMonLimitSessDestread-onlycurrentThe user can limit the number of concurrent sessions to the same destination IP address. A wily attacker can launch a distributed denial-of-service (DDoS) atta…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.30ColumnjnxJsScreenMonSynAckAckread-onlycurrentWhen an authentication user initiates a Telnet or FTP connection, the user sends a SYN segment to the Telnet or FTP server. The device intercepts the SYN segme…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.31ColumnjnxJsScreenMonIpFragread-onlycurrentAs packets travels, it is sometimes necessary to break a packet into smaller fragments based upon the maximum transmission unit (MTU) of each network. IP fragm…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.32ColumnjnxJsScreenSynAttackThreshread-onlycurrentThe number of SYN segments to the same destination address and port number per second required to activate the SYN proxying mechanism. In order to set the appr…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.33ColumnjnxJsScreenSynAttackTimeoutread-onlycurrentThe maximum length of time before a half-completed connection is dropped from the queue. The default is 20 seconds. This attributes display the SYN attack time…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.34ColumnjnxJsScreenSynAttackAlmThread-onlycurrentThe syn attack alarm threshold causes an alarm to be generated when the number of proxied, half-complete TCP connection requests per second requests to the sam…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.35ColumnjnxJsScreenSynAttackQueSizeread-onlydeprecatedThe number of proxied connection requests held in the proxied connection queue before the device starts rejecting new connection requests. This attribute displ…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.36ColumnjnxJsScreenSynAttackAgeTimeread-onlydeprecatedSYN flood age time. This object has been deprecated.
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.37ColumnjnxJsScreenIcmpFloodThreshread-onlycurrentICMP flooding occurs when an attacker sends IP packets containing ICMP datagrams with the purpose of slowing down the victim to the point that it can no longer…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.38ColumnjnxJsScreenUdpFloodThreshread-onlycurrentUDP flooding occurs when an attacker sends IP packets containing UDP datagrams with the purpose of slowing down the victim to the point that it can no longer h…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.39ColumnjnxJsScreenPortScanThreshread-onlycurrentThe port scan threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default setti…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.40ColumnjnxJsScreenIpSweepThreshread-onlycurrentThe IP sweep threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default settin…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.41ColumnjnxJsScreenSynAckAckThresread-onlycurrentSYN ack ack alarm threshold value.
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.42ColumnjnxJsScreenMonIpv6ExtHdrread-onlycurrentIn one IPv6 packet, one or more extension headers may appear before the encapsulated payload after the mandatory header. User can screen any one or several ext…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.43ColumnjnxJsScreenMonIpv6HopOptread-onlycurrentIn one IPv6 hop by hop option extension header, it carries a variable number options. User can screen any one or several options. When the hop by hop option sc…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.44ColumnjnxJsScreenMonIpv6DstOptread-onlycurrentIn one IPv6 destination option extension header, it carries a variable number options. User can screen any one or several options. When the destination option …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.45ColumnjnxJsScreenMonIpv6ExtLimitread-onlycurrentIn one IPv6 packet, one or more extension headers may appear before the encapsulated payload. User can screen IPv6 packets if their extension header number is …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.46ColumnjnxJsScreenMonIpMalIpv6read-onlycurrentOne IPv6 packets may contain malformed header, the device tries to block these packets to protect downstream devices. When the malformed IPv6 screen is enabled…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.47ColumnjnxJsScreenMonIcmpMalIcmpv6read-onlycurrentOne ICMPv6 packets may contain malformed content, the device tries to block these packets to protect downstream devices. When the malformed ICMPv6 screen is en…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.48ColumnjnxJsScreenIpv6ExtNumLimread-onlycurrentIPv6 extension header number limit value.
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.49ColumnjnxJsScreenUdpPortScanThreshread-onlycurrentThe UDP port scan threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default s…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.50ColumnjnxJsScreenMonUdpPortScanread-onlycurrentA UDP port scan occurs when one source IP address sends UDP packets to a defined number of different ports at the same destination IP address within a defined …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.51ColumnjnxJsScreenMonIpTunnelGre6in4read-onlycurrentWhen an IP GRE 6in4 Tunnel packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute records t…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.52ColumnjnxJsScreenMonIpTunnelGre4in6read-onlycurrentWhen an IP GRE 4in6 Tunnel packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute records t…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.53ColumnjnxJsScreenMonIpTunnelGre6in6read-onlycurrentWhen an IP GRE 6in6 Tunnel packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute records t…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.54ColumnjnxJsScreenMonIpTunnelGre4in4read-onlycurrentWhen an IP GRE 4in4 Tunnel packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute records t…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.55ColumnjnxJsScreenMonIpTunnelIpInUdpTeredoread-onlycurrentWhen an IPinUDP Teredo Tunnel packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute record…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.56ColumnjnxJsScreenMonIpTunnelBadInnerHeaderread-onlycurrentWhen an IP Tunnel Bad Inner Header packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute r…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.57ColumnjnxJsScreenMonIpTunnelIpIp6to4relayread-onlycurrentWhen an IP Tunnel IPinIP 6to4 relay packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.58ColumnjnxJsScreenMonIpTunnelIpIp6in4read-onlycurrentWhen an IP Tunnel IPinIP 6in4 packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute record…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.59ColumnjnxJsScreenMonIpTunnelIpIp6over4read-onlycurrentWhen an IP Tunnel IPinIP 6over4 packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute reco…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.60ColumnjnxJsScreenMonIpTunnelIpIp4in6read-onlycurrentWhen an IP Tunnel IPinIP 4in6 packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute record…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.61ColumnjnxJsScreenMonIpTunnelIpIp4in4read-onlycurrentWhen an IP Tunnel IPinIP 4in4 packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute record…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.62ColumnjnxJsScreenMonIpTunnelIpIp6in6read-onlycurrentWhen an IP Tunnel IPinIP 6in6 packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute record…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.63ColumnjnxJsScreenMonIpTunnelIpIpIsatapread-onlycurrentWhen an IP Tunnel IPinIP ISATAP packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute reco…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.64ColumnjnxJsScreenMonIpTunnelIpIpDsLiteread-onlycurrentWhen an IP Tunnel IPinIP DS-Lite packet meets the attack criteria specified by current configuration, it will be counted in this statisitic. This attribute rec…
1.3.6.1.4.1.2636.3.39.1.8.1.1.2TablejnxJsScreenMonThreshTablenot-accessiblecurrentThis table is a read-only table that augments the jnxJsScreenMonTable. The purpose of this table is to keep threshold and counter information about Syn Flood a…
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1RowjnxJsScreenMonThreshEntryread-onlycurrentSyn Flood and Session Limit thresholds and counts.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.1ColumnjnxJsScreenSynFloodSrcThreshread-onlycurrentThe number of SYN segments received per second from a single source IP - regardless of the destination IP address and port number - before the security device …
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.2ColumnjnxJsScreenSynFloodDstThreshread-onlycurrentThe number of SYN segments received per second from a single destination IP address before the security device begins dropping connection requests to that dest…
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.3ColumnjnxJsScreenSessLimitSrcThreshread-onlycurrentThe security device can impose a limit on the number of SYN segments permitted from a single source IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.4ColumnjnxJsScreenSessLimitDstThreshread-onlycurrentThe security device can impose a limit on the number of SYN segments permitted to a single destination IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.5ColumnjnxJsScreenMonSynFloodSrcread-onlycurrentThe number of concurrent sessions from the same source IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.6ColumnjnxJsScreenMonSynFloodDstread-onlycurrentThe number of concurrent sessions to the same destination IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.1.3TablejnxJsScreenSweepTablenot-accessiblecurrentThis table is a read-only table that augments the jnxJsScreenMonTable. The purpose of this table is to add counters and thresholds for TCP/UDP sweep feature.
1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1RowjnxJsScreenSweepEntrynot-accessiblecurrentTCP/UDP sweep thresholds and counters.
1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.1ColumnjnxJsScreenTcpSweepThreshread-onlycurrentThe TCP sweep threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default setti…
1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.2ColumnjnxJsScreenUdpSweepThreshread-onlycurrentThe UDP sweep threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default setti…
1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.3ColumnjnxJsScreenMonTcpSweepread-onlycurrentThe number of TCP sessions dropped due to TCP sweeping attack.
1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.4ColumnjnxJsScreenMonUdpSweepread-onlycurrentThe number of UDP packets dropped due to UDP sweeping attack.
1.3.6.1.4.1.2636.3.39.1.8.1.2NodejnxJsScreenTrapVars
1.3.6.1.4.1.2636.3.39.1.8.1.2.1ScalarjnxJsScreenAttackTypeaccessible-for-notifycurrentThe type of attacks that the device support.
1.3.6.1.4.1.2636.3.39.1.8.1.2.2ScalarjnxJsScreenAttackCounteraccessible-for-notifycurrentThe threshold value that triggers the trap to be generated.
1.3.6.1.4.1.2636.3.39.1.8.1.2.3ScalarjnxJsScreenAttackDescraccessible-for-notifycurrentThe description pertinent to the attack trap.
1.3.6.1.4.1.2636.3.39.1.8.1.2.4ScalarjnxJsScreenCfgStatusaccessible-for-notifycurrentThe screening option configuration status: enabled or disabled.