All MIBs › JUNIPER-JS-SCREENING-MIB › jnxJsScreenMonIpFrag
jnxJsScreenMonIpFrag
Module: JUNIPER-JS-SCREENING-MIB
OID (symbolic): JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIpFrag
OID (numeric): 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.31
Node type: OBJECT-TYPE
Type: Counter64
Access: read-only
Description: As packets travels, it is sometimes necessary to break a packet into smaller fragments based upon the maximum transmission unit (MTU) of each network. IP fragments might contain an attacker's attempt to exploit the vulnerabilities in the packet reassembly code of specific IP stack implementations. When the victim receives these packets, the results can range from processing the packets incorrectly to crashing the entire system.
When the block IP framentation flag is enabled, the device blocks all IP packet fragments that it receives at interfaces bound to that zone.
This attribute counts the number of block IP fragment packets.
What is jnxJsScreenMonIpFrag?
This read-only counter tallies IP fragment packets blocked in this zone, applicable when the zone is configured to reject all IP fragmentation outright since fragments can be crafted to exploit vulnerabilities in a target's reassembly code. An admin watching this counter climb confirms the zone's blanket anti-fragmentation policy is actively dropping fragmented traffic.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.31 snmpwalk -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIpFrag
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.31.1 snmpget -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIpFrag.1
Start monitoring Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonIpFrag OID value, configure state conditions and alerts, and monitor any Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) from a single console.
OID Breakdown
Upper-level ancestors (11 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.2636 | juniperMIB | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3 | jnxMibs | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39 | jnxJsMibRoot | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39.1 | jnxJsSecurity | JUNIPER-JS-SMI |
| 1.3.6.1.4.1.2636.3.39.1.8 | jnxJsScreening | JUNIPER-JS-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.2636.3.39.1.8.1 | jnxJsScreenMIB | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1 | jnxJsScreenObjects | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1 | jnxJsScreenMonTable | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1 | jnxJsScreenMonEntry | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.31 | jnxJsScreenMonIpFrag | JUNIPER-JS-SCREENING-MIB |