MIB Viewer

JUNIPER-JS-SCREENING-MIB

61 objects
This module defines the MIB for Juniper Enterprise Firewall screen functionality. Juniper documentation is recommended as the reference. Juniper Security Firewall provides various detection methods and defense mechanisms to combat exploits at all stages of the path of execution. These includes: Setting screen options Firwall DOS attacks Network DOS attack OS specific DOS attack Fragment reassembly
Imported Objects
IF-MIBifName
JUNIPER-JS-SMIjnxJsScreening
SNMPv2-SMICounter64 Integer32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE
SNMPv2-TCDisplayString
OIDNameAccessStatusDescription
1.3.6.1.4.1.2636.3.39.1.8.1IdentityjnxJsScreenMIBThis module defines the MIB for Juniper Enterprise Firewall screen functionality. Juniper documentation is recommended as the reference. Juniper Security Firew…
1.3.6.1.4.1.2636.3.39.1.8.1.0NodejnxJsScreenNotifications
1.3.6.1.4.1.2636.3.39.1.8.1.0.1NotificationjnxJsScreenAttackcurrentA per min bytes exceed trap signifies that the number of bytes per minutes has exceeds the specified threshold. jnxJsScreenZoneName: the zone name under which …
1.3.6.1.4.1.2636.3.39.1.8.1.0.2NotificationjnxJsScreenCfgChangecurrentThe screening configuration change trap signifies that an screening option has been changed(enabled or disabled). A disable feature may implies a security hole…
1.3.6.1.4.1.2636.3.39.1.8.1.1NodejnxJsScreenObjects
1.3.6.1.4.1.2636.3.39.1.8.1.1.1TablejnxJsScreenMonTablenot-accessiblecurrentJuniper security Firewall can allow DI protection on each of the device's physical interface. This table collects the screen attributes that monitor the variou…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1RowjnxJsScreenMonEntrynot-accessiblecurrentThe screen option monitoring statistics entry. Each entry is uniquely identified by the zone name. The data is collected on a per zone basis. There can be mult…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.1ColumnjnxJsScreenZoneNameaccessible-for-notifycurrentThe name of the security zone under which the statistics are collected.
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.2ColumnjnxJsScreenNumOfIfread-onlycurrentNumber of interfaces bound to this zone. Each counter contains the aggregated data of all the interfaces
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.3ColumnjnxJsScreenMonSynAttkread-onlycurrentThe SYN (TCP connection request) attack is a common denial of service (DoS) technique characterized by the following pattern: - Using a spoofed IP address not …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.4ColumnjnxJsScreenMonTearDropread-onlycurrentTeardrop attacks exploit the reassembly of fragmented IP packets. In the IP header, one of the fields is the fragment offset field, which indicates one of the …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.5ColumnjnxJsScreenMonSrcRouteread-onlycurrentIP source route options can be used to hide their true address and access restricted areas of a network by specifying a different path. The security device sho…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.6ColumnjnxJsScreenMonPingDeathread-onlycurrentThe maximum allowable IP packet size is 65,535 bytes, including the packet header (typically 20 bytes long). An ICMP echo request is an IP packet with a pseudo…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.7ColumnjnxJsScreenMonAddrSpoofread-onlycurrentOne method to gain access to a restricted network is to insert a bogus source address in the packet header to make the packet appear to come from a trusted sou…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.8ColumnjnxJsScreenMonLandread-onlycurrentA combined SYN attack with IP spoof is referred to as Land attack. A Land attack occurs when an attacker sends spoofed SYN packets containing the IP address of…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.9ColumnjnxJsScreenMonIcmpFloodread-onlycurrentAn ICMP flood typically occurs when ICMP echo requests overload its victim with so many requests that it expends all its resources responding until it can no l…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.10ColumnjnxJsScreenMonUdpFloodread-onlycurrentUDP flooding occurs when an attacker sends IP packets containing UDP datagrams with the purpose of slowing down the victim to the point that it can no longer h…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.11ColumnjnxJsScreenMonWinnukeread-onlycurrentWinNuke is a DoS attack targeting any computer on the internet running Windows. The attacker sends a TCP segment, usually to NetBIOS port 139 with the urgent (…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.12ColumnjnxJsScreenMonPortScanread-onlycurrentA port scan occurs when one source IP address sends IP packets containing TCP SYN segments to a defined number of different ports at the same destination IP ad…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.13ColumnjnxJsScreenMonIpSweepread-onlycurrentAn address sweep occurs when one source IP address sends a defined number of ICMP packets to different hosts within a defined interval. The purpose of this att…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.14ColumnjnxJsScreenMonSynFragread-onlycurrentIP encapsulates a TCP SYN segment in the IP packet that initiates a TCP connection. The purpose is to initiate a connection and to invoke a SYN/ACK segment res…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.15ColumnjnxJsScreenMonTcpNoFlagread-onlycurrentA normal TCP segment header has at least one flag control set. A TCP segment with no control flags set is an anomalous event. Operating systems respond to such…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.16ColumnjnxJsScreenMonIpUnknownProtread-onlycurrentAccording to RFC 1700, some protocol types in IP header are reserved and unassigned at this time. Precisely because these protocols are undefined, there is no …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.17ColumnjnxJsScreenMonIpOptBadread-onlycurrentIP protocol specifies a set of eight options that provide special routing controls, diagnostic tools, and security. These eight options can be used for malicio…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.18ColumnjnxJsScreenMonIpOptRecRtread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.19ColumnjnxJsScreenMonIpOptTimestampread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.20ColumnjnxJsScreenMonIpOptSecurityread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.21ColumnjnxJsScreenMonIpOptLSRread-onlycurrentAttackers can use IP source route options to hide their true address and access restricted areas of a network by specifying a different path. The security devi…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.22ColumnjnxJsScreenMonIpOptSSRread-onlycurrentAttackers can use IP source route options to hide their true address and access restricted areas of a network by specifying a different path. The security devi…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.23ColumnjnxJsScreenMonIpOptStreamread-onlycurrentThe IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.24ColumnjnxJsScreenMonIcmpFragread-onlycurrentICMP provides error reporting and network probe capabilities. ICMP packets contain very short messages, there is no legitimate reason for ICMP packets to be fr…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.25ColumnjnxJsScreenMonIcmpLargeread-onlycurrentICMP packets contain very short messages, there is no legitimate reason for ICMP packets to be fragmented. If an ICMP packet is unusually large, something is w…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.26ColumnjnxJsScreenMonTcpSynFinread-onlycurrentBoth the SYN and FIN control flags are not normally set in the same TCP segment header. The SYN flag synchronizes sequence numbers to initiate a TCP connection…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.27ColumnjnxJsScreenMonTcpFinNoAckread-onlycurrentA FIN scan sends TCP segments with the FIN flag set in an attempt to provoke a response and thereby discover an active host or an active port on a host. The us…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.28ColumnjnxJsScreenMonLimitSessSrcread-onlycurrentAll the virus-generated traffic originates from the same IP address (generally from a infected server), a source-based session limit ensures that the firewall …
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.29ColumnjnxJsScreenMonLimitSessDestread-onlycurrentThe user can limit the number of concurrent sessions to the same destination IP address. A wily attacker can launch a distributed denial-of-service (DDoS) atta…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.30ColumnjnxJsScreenMonSynAckAckread-onlycurrentWhen an authentication user initiates a Telnet or FTP connection, the user sends a SYN segment to the Telnet or FTP server. The device intercepts the SYN segme…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.31ColumnjnxJsScreenMonIpFragread-onlycurrentAs packets travels, it is sometimes necessary to break a packet into smaller fragments based upon the maximum transmission unit (MTU) of each network. IP fragm…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.32ColumnjnxJsScreenSynAttackThreshread-onlycurrentThe number of SYN segments to the same destination address and port number per second required to activate the SYN proxying mechanism. In order to set the appr…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.33ColumnjnxJsScreenSynAttackTimeoutread-onlycurrentThe maximum length of time before a half-completed connection is dropped from the queue. The default is 20 seconds. This attributes display the SYN attack time…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.34ColumnjnxJsScreenSynAttackAlmThread-onlycurrentThe syn attack alarm threshold causes an alarm to be generated when the number of proxied, half-complete TCP connection requests per second requests to the sam…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.35ColumnjnxJsScreenSynAttackQueSizeread-onlydeprecatedThe number of proxied connection requests held in the proxied connection queue before the device starts rejecting new connection requests. This attribute displ…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.36ColumnjnxJsScreenSynAttackAgeTimeread-onlydeprecatedSYN flood age time. This object has been deprecated.
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.37ColumnjnxJsScreenIcmpFloodThreshread-onlycurrentICMP flooding occurs when an attacker sends IP packets containing ICMP datagrams with the purpose of slowing down the victim to the point that it can no longer…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.38ColumnjnxJsScreenUdpFloodThreshread-onlycurrentUDP flooding occurs when an attacker sends IP packets containing UDP datagrams with the purpose of slowing down the victim to the point that it can no longer h…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.39ColumnjnxJsScreenPortScanThreshread-onlycurrentThe port scan threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default setti…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.40ColumnjnxJsScreenIpSweepThreshread-onlycurrentThe IP sweep threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default settin…
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.41ColumnjnxJsScreenSynAckAckThresread-onlycurrentSYN ack ack alarm threshold value.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2TablejnxJsScreenMonThreshTablenot-accessiblecurrentThis table is a read-only table that augments the jnxJsScreenMonTable. The purpose of this table is to keep threshold and counter information about Syn Flood a…
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1RowjnxJsScreenMonThreshEntryread-onlycurrentSyn Flood and Session Limit thresholds and counts.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.1ColumnjnxJsScreenSynFloodSrcThreshread-onlycurrentThe number of SYN segments received per second from a single source IP - regardless of the destination IP address and port number - before the security device …
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.2ColumnjnxJsScreenSynFloodDstThreshread-onlycurrentThe number of SYN segments received per second from a single destination IP address before the security device begins dropping connection requests to that dest…
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.3ColumnjnxJsScreenSessLimitSrcThreshread-onlycurrentThe security device can impose a limit on the number of SYN segments permitted from a single source IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.4ColumnjnxJsScreenSessLimitDstThreshread-onlycurrentThe security device can impose a limit on the number of SYN segments permitted to a single destination IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.5ColumnjnxJsScreenMonSynFloodSrcread-onlycurrentThe number of concurrent sessions from the same source IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.6ColumnjnxJsScreenMonSynFloodDstread-onlycurrentThe number of concurrent sessions to the same destination IP address.
1.3.6.1.4.1.2636.3.39.1.8.1.2NodejnxJsScreenTrapVars
1.3.6.1.4.1.2636.3.39.1.8.1.2.1ScalarjnxJsScreenAttackTypeaccessible-for-notifycurrentThe type of attacks that the device support.
1.3.6.1.4.1.2636.3.39.1.8.1.2.2ScalarjnxJsScreenAttackCounteraccessible-for-notifycurrentThe threshold value that triggers the trap to be generated.
1.3.6.1.4.1.2636.3.39.1.8.1.2.3ScalarjnxJsScreenAttackDescraccessible-for-notifycurrentThe description pertinent to the attack trap.
1.3.6.1.4.1.2636.3.39.1.8.1.2.4ScalarjnxJsScreenCfgStatusaccessible-for-notifycurrentThe screening option configuration status: enabled or disabled.