All MIBs › JUNIPER-JS-SCREENING-MIB › jnxJsScreenMonAddrSpoof
jnxJsScreenMonAddrSpoof
Module: JUNIPER-JS-SCREENING-MIB
OID (symbolic): JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonAddrSpoof
OID (numeric): 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.7
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: One method to gain access to a restricted network is to insert a bogus source address in the packet header to make the packet appear to come from a trusted source. This technique is called IP spoofing. The mechanism to detect IP spoofing relies on route table entries.
For example, if a packet with source IP address 10.1.1.6 arrives at port eth3, but the device has a route to 10.1.1.0/24 through port eth1. IP spoofing checking notes that this address arrived at an invalid interface as defined in the route table. A valid packet from 10.1.1.6 can only arrive via eth1, not eth3. The device concludes that the packet has a spoofed source IP address and discards it.
This attribute records the address spoofing attack packets.
What is jnxJsScreenMonAddrSpoof?
This read-only counter tallies IP address-spoofing attack packets caught in this zone, detected when a packet's source address arrives on an interface that the device's route table says shouldn't carry traffic from that address. An admin watching this counter climb knows someone is trying to impersonate a trusted source IP to bypass access controls.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.7 snmpwalk -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonAddrSpoof
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.7.1 snmpget -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonAddrSpoof.1
Start monitoring Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonAddrSpoof OID value, configure state conditions and alerts, and monitor any Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) from a single console.
OID Breakdown
Upper-level ancestors (11 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.2636 | juniperMIB | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3 | jnxMibs | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39 | jnxJsMibRoot | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39.1 | jnxJsSecurity | JUNIPER-JS-SMI |
| 1.3.6.1.4.1.2636.3.39.1.8 | jnxJsScreening | JUNIPER-JS-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.2636.3.39.1.8.1 | jnxJsScreenMIB | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1 | jnxJsScreenObjects | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1 | jnxJsScreenMonTable | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1 | jnxJsScreenMonEntry | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.7 | jnxJsScreenMonAddrSpoof | JUNIPER-JS-SCREENING-MIB |