All MIBs › JUNIPER-JS-SCREENING-MIB › jnxJsScreenMonIcmpLarge
jnxJsScreenMonIcmpLarge
Module: JUNIPER-JS-SCREENING-MIB
OID (symbolic): JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIcmpLarge
OID (numeric): 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.25
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: ICMP packets contain very short messages, there is no legitimate reason for ICMP packets to be fragmented.
If an ICMP packet is unusually large, something is wrong. For example, the Loki program uses ICMP as a channel for transmitting covert messages. The presence of large ICMP packets might expose a compromised machine acting as a Loki agent. It might also indicate some other kind of shifty activity.
When the the Large Size ICMP Packet Protection SCREEN option is enabled, the device drops ICMP packets with a length greater than 1024 bytes.
This attribute records the detection of large ICMP packets.
What is jnxJsScreenMonIcmpLarge?
This read-only counter tallies oversized ICMP packets dropped in this zone, specifically ones exceeding 1024 bytes by default, since legitimately short ICMP messages have no reason to be that large and oversized ones can indicate a covert channel like the Loki tool. An admin watching this counter climb should treat it as a possible sign of a compromised host tunneling data over ICMP.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.25 snmpwalk -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIcmpLarge
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.25.1 snmpget -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIcmpLarge.1
Start monitoring Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIcmpLarge OID value, configure state conditions and alerts, and monitor any Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) from a single console.
OID Breakdown
Upper-level ancestors (11 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.2636 | juniperMIB | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3 | jnxMibs | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39 | jnxJsMibRoot | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39.1 | jnxJsSecurity | JUNIPER-JS-SMI |
| 1.3.6.1.4.1.2636.3.39.1.8 | jnxJsScreening | JUNIPER-JS-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.2636.3.39.1.8.1 | jnxJsScreenMIB | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1 | jnxJsScreenObjects | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1 | jnxJsScreenMonTable | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1 | jnxJsScreenMonEntry | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.25 | jnxJsScreenMonIcmpLarge | JUNIPER-JS-SCREENING-MIB |