JUNIPER-JS-SCREENING-MIB
61 objects
This module defines the MIB for Juniper Enterprise Firewall screen functionality. Juniper documentation is recommended as the reference. Juniper Security Firewall provides various detection methods and defense mechanisms to combat exploits at all stages of the path of execution. These includes: Setting screen options Firwall DOS attacks Network DOS attack OS specific DOS attack Fragment reassembly
Imported Objects
| IF-MIB | ifName |
| JUNIPER-JS-SMI | jnxJsScreening |
| SNMPv2-SMI | Counter64 Integer32 MODULE-IDENTITY NOTIFICATION-TYPE OBJECT-TYPE |
| SNMPv2-TC | DisplayString |
| OID | Name | Access | Status | Description |
|---|---|---|---|---|
| 1.3.6.1.4.1.2636.3.39.1.8.1 | IdentityjnxJsScreenMIB | This module defines the MIB for Juniper Enterprise Firewall screen functionality. Juniper documentation is recommended as the reference. Juniper Security Firew… | ||
| 1.3.6.1.4.1.2636.3.39.1.8.1.0 | NodejnxJsScreenNotifications | |||
| 1.3.6.1.4.1.2636.3.39.1.8.1.0.1 | NotificationjnxJsScreenAttack | current | A per min bytes exceed trap signifies that the number of bytes per minutes has exceeds the specified threshold. jnxJsScreenZoneName: the zone name under which … | |
| 1.3.6.1.4.1.2636.3.39.1.8.1.0.2 | NotificationjnxJsScreenCfgChange | current | The screening configuration change trap signifies that an screening option has been changed(enabled or disabled). A disable feature may implies a security hole… | |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1 | NodejnxJsScreenObjects | |||
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1 | TablejnxJsScreenMonTable | not-accessible | current | Juniper security Firewall can allow DI protection on each of the device's physical interface. This table collects the screen attributes that monitor the variou… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1 | RowjnxJsScreenMonEntry | not-accessible | current | The screen option monitoring statistics entry. Each entry is uniquely identified by the zone name. The data is collected on a per zone basis. There can be mult… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.1 | ColumnjnxJsScreenZoneName | accessible-for-notify | current | The name of the security zone under which the statistics are collected. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.2 | ColumnjnxJsScreenNumOfIf | read-only | current | Number of interfaces bound to this zone. Each counter contains the aggregated data of all the interfaces |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.3 | ColumnjnxJsScreenMonSynAttk | read-only | current | The SYN (TCP connection request) attack is a common denial of service (DoS) technique characterized by the following pattern: - Using a spoofed IP address not … |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.4 | ColumnjnxJsScreenMonTearDrop | read-only | current | Teardrop attacks exploit the reassembly of fragmented IP packets. In the IP header, one of the fields is the fragment offset field, which indicates one of the … |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.5 | ColumnjnxJsScreenMonSrcRoute | read-only | current | IP source route options can be used to hide their true address and access restricted areas of a network by specifying a different path. The security device sho… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.6 | ColumnjnxJsScreenMonPingDeath | read-only | current | The maximum allowable IP packet size is 65,535 bytes, including the packet header (typically 20 bytes long). An ICMP echo request is an IP packet with a pseudo… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.7 | ColumnjnxJsScreenMonAddrSpoof | read-only | current | One method to gain access to a restricted network is to insert a bogus source address in the packet header to make the packet appear to come from a trusted sou… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.8 | ColumnjnxJsScreenMonLand | read-only | current | A combined SYN attack with IP spoof is referred to as Land attack. A Land attack occurs when an attacker sends spoofed SYN packets containing the IP address of… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.9 | ColumnjnxJsScreenMonIcmpFlood | read-only | current | An ICMP flood typically occurs when ICMP echo requests overload its victim with so many requests that it expends all its resources responding until it can no l… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.10 | ColumnjnxJsScreenMonUdpFlood | read-only | current | UDP flooding occurs when an attacker sends IP packets containing UDP datagrams with the purpose of slowing down the victim to the point that it can no longer h… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.11 | ColumnjnxJsScreenMonWinnuke | read-only | current | WinNuke is a DoS attack targeting any computer on the internet running Windows. The attacker sends a TCP segment, usually to NetBIOS port 139 with the urgent (… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.12 | ColumnjnxJsScreenMonPortScan | read-only | current | A port scan occurs when one source IP address sends IP packets containing TCP SYN segments to a defined number of different ports at the same destination IP ad… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.13 | ColumnjnxJsScreenMonIpSweep | read-only | current | An address sweep occurs when one source IP address sends a defined number of ICMP packets to different hosts within a defined interval. The purpose of this att… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.14 | ColumnjnxJsScreenMonSynFrag | read-only | current | IP encapsulates a TCP SYN segment in the IP packet that initiates a TCP connection. The purpose is to initiate a connection and to invoke a SYN/ACK segment res… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.15 | ColumnjnxJsScreenMonTcpNoFlag | read-only | current | A normal TCP segment header has at least one flag control set. A TCP segment with no control flags set is an anomalous event. Operating systems respond to such… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.16 | ColumnjnxJsScreenMonIpUnknownProt | read-only | current | According to RFC 1700, some protocol types in IP header are reserved and unassigned at this time. Precisely because these protocols are undefined, there is no … |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.17 | ColumnjnxJsScreenMonIpOptBad | read-only | current | IP protocol specifies a set of eight options that provide special routing controls, diagnostic tools, and security. These eight options can be used for malicio… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.18 | ColumnjnxJsScreenMonIpOptRecRt | read-only | current | The IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.19 | ColumnjnxJsScreenMonIpOptTimestamp | read-only | current | The IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.20 | ColumnjnxJsScreenMonIpOptSecurity | read-only | current | The IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.21 | ColumnjnxJsScreenMonIpOptLSR | read-only | current | Attackers can use IP source route options to hide their true address and access restricted areas of a network by specifying a different path. The security devi… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.22 | ColumnjnxJsScreenMonIpOptSSR | read-only | current | Attackers can use IP source route options to hide their true address and access restricted areas of a network by specifying a different path. The security devi… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.23 | ColumnjnxJsScreenMonIpOptStream | read-only | current | The IP standard RFC 791 specifies a set of options to provide special routing controls, diagnostic tools, and security. These options appear after the destinat… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.24 | ColumnjnxJsScreenMonIcmpFrag | read-only | current | ICMP provides error reporting and network probe capabilities. ICMP packets contain very short messages, there is no legitimate reason for ICMP packets to be fr… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.25 | ColumnjnxJsScreenMonIcmpLarge | read-only | current | ICMP packets contain very short messages, there is no legitimate reason for ICMP packets to be fragmented. If an ICMP packet is unusually large, something is w… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.26 | ColumnjnxJsScreenMonTcpSynFin | read-only | current | Both the SYN and FIN control flags are not normally set in the same TCP segment header. The SYN flag synchronizes sequence numbers to initiate a TCP connection… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.27 | ColumnjnxJsScreenMonTcpFinNoAck | read-only | current | A FIN scan sends TCP segments with the FIN flag set in an attempt to provoke a response and thereby discover an active host or an active port on a host. The us… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.28 | ColumnjnxJsScreenMonLimitSessSrc | read-only | current | All the virus-generated traffic originates from the same IP address (generally from a infected server), a source-based session limit ensures that the firewall … |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.29 | ColumnjnxJsScreenMonLimitSessDest | read-only | current | The user can limit the number of concurrent sessions to the same destination IP address. A wily attacker can launch a distributed denial-of-service (DDoS) atta… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.30 | ColumnjnxJsScreenMonSynAckAck | read-only | current | When an authentication user initiates a Telnet or FTP connection, the user sends a SYN segment to the Telnet or FTP server. The device intercepts the SYN segme… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.31 | ColumnjnxJsScreenMonIpFrag | read-only | current | As packets travels, it is sometimes necessary to break a packet into smaller fragments based upon the maximum transmission unit (MTU) of each network. IP fragm… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.32 | ColumnjnxJsScreenSynAttackThresh | read-only | current | The number of SYN segments to the same destination address and port number per second required to activate the SYN proxying mechanism. In order to set the appr… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.33 | ColumnjnxJsScreenSynAttackTimeout | read-only | current | The maximum length of time before a half-completed connection is dropped from the queue. The default is 20 seconds. This attributes display the SYN attack time… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.34 | ColumnjnxJsScreenSynAttackAlmTh | read-only | current | The syn attack alarm threshold causes an alarm to be generated when the number of proxied, half-complete TCP connection requests per second requests to the sam… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.35 | ColumnjnxJsScreenSynAttackQueSize | read-only | deprecated | The number of proxied connection requests held in the proxied connection queue before the device starts rejecting new connection requests. This attribute displ… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.36 | ColumnjnxJsScreenSynAttackAgeTime | read-only | deprecated | SYN flood age time. This object has been deprecated. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.37 | ColumnjnxJsScreenIcmpFloodThresh | read-only | current | ICMP flooding occurs when an attacker sends IP packets containing ICMP datagrams with the purpose of slowing down the victim to the point that it can no longer… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.38 | ColumnjnxJsScreenUdpFloodThresh | read-only | current | UDP flooding occurs when an attacker sends IP packets containing UDP datagrams with the purpose of slowing down the victim to the point that it can no longer h… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.39 | ColumnjnxJsScreenPortScanThresh | read-only | current | The port scan threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default setti… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.40 | ColumnjnxJsScreenIpSweepThresh | read-only | current | The IP sweep threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000. By using the default settin… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.41 | ColumnjnxJsScreenSynAckAckThres | read-only | current | SYN ack ack alarm threshold value. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2 | TablejnxJsScreenMonThreshTable | not-accessible | current | This table is a read-only table that augments the jnxJsScreenMonTable. The purpose of this table is to keep threshold and counter information about Syn Flood a… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1 | RowjnxJsScreenMonThreshEntry | read-only | current | Syn Flood and Session Limit thresholds and counts. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.1 | ColumnjnxJsScreenSynFloodSrcThresh | read-only | current | The number of SYN segments received per second from a single source IP - regardless of the destination IP address and port number - before the security device … |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.2 | ColumnjnxJsScreenSynFloodDstThresh | read-only | current | The number of SYN segments received per second from a single destination IP address before the security device begins dropping connection requests to that dest… |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.3 | ColumnjnxJsScreenSessLimitSrcThresh | read-only | current | The security device can impose a limit on the number of SYN segments permitted from a single source IP address. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.4 | ColumnjnxJsScreenSessLimitDstThresh | read-only | current | The security device can impose a limit on the number of SYN segments permitted to a single destination IP address. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.5 | ColumnjnxJsScreenMonSynFloodSrc | read-only | current | The number of concurrent sessions from the same source IP address. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.2.1.6 | ColumnjnxJsScreenMonSynFloodDst | read-only | current | The number of concurrent sessions to the same destination IP address. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.2 | NodejnxJsScreenTrapVars | |||
| 1.3.6.1.4.1.2636.3.39.1.8.1.2.1 | ScalarjnxJsScreenAttackType | accessible-for-notify | current | The type of attacks that the device support. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.2.2 | ScalarjnxJsScreenAttackCounter | accessible-for-notify | current | The threshold value that triggers the trap to be generated. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.2.3 | ScalarjnxJsScreenAttackDescr | accessible-for-notify | current | The description pertinent to the attack trap. |
| 1.3.6.1.4.1.2636.3.39.1.8.1.2.4 | ScalarjnxJsScreenCfgStatus | accessible-for-notify | current | The screening option configuration status: enabled or disabled. |