JUNIPER-JS-SCREENING-MIB :: jnxJsScreenMonSynAckAck

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsJUNIPER-JS-SCREENING-MIBjnxJsScreenMonSynAckAck

jnxJsScreenMonSynAckAck

Module: JUNIPER-JS-SCREENING-MIB

OID (symbolic): JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynAckAck

OID (numeric): 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.30

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: When an authentication user initiates a Telnet or FTP connection, the user sends a SYN segment to the Telnet or FTP server. The device intercepts the SYN segment, creates an entry in its session table, and proxies a SYN-ACK segment to the user. The user then replies with an ACK segment. At that point, the initial 3-way handshake is complete. The device sends a login prompt to the user. When a malicisou user does not log in, but instead continue initiating SYN-ACK-ACK sessions, the firewall session table can fill up to the point where the device begins rejecting legitimate connection requests.

When the SYN-ACK-ACK proxy protection option is enabled, after the number of connections from the same IP address reaches the SYN-ACK-ACK proxy threshold, the device rejects further connection requests from that IP address. By default, the threshold is 512 connections from any single IP address.

The attribute records the detection of SYN ACK ACK attack.

What is jnxJsScreenMonSynAckAck?

This read-only counter tallies SYN-ACK-ACK proxy attacks caught in this zone, where a malicious client repeatedly completes the TCP 3-way handshake toward a Telnet/FTP proxy without ever logging in, aiming to fill the firewall's session table; the device rejects further attempts from that source once it exceeds the configured threshold (512 by default). An admin watching this counter climb knows the device is blocking a session-table exhaustion attempt targeting proxied login services.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.30
snmpwalk -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynAckAck

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.30.1
snmpget -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynAckAck.1

Start monitoring Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynAckAck OID value, configure state conditions and alerts, and monitor any Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) from a single console.

OID Breakdown

Upper-level ancestors (11 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.2636juniperMIBJUNIPER-SMI
1.3.6.1.4.1.2636.3jnxMibsJUNIPER-SMI
1.3.6.1.4.1.2636.3.39jnxJsMibRootJUNIPER-SMI
1.3.6.1.4.1.2636.3.39.1jnxJsSecurityJUNIPER-JS-SMI
1.3.6.1.4.1.2636.3.39.1.8jnxJsScreeningJUNIPER-JS-SMI
Numeric OIDNameModule
1.3.6.1.4.1.2636.3.39.1.8.1jnxJsScreenMIBJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1jnxJsScreenObjectsJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1.1jnxJsScreenMonTableJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1jnxJsScreenMonEntryJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.30jnxJsScreenMonSynAckAckJUNIPER-JS-SCREENING-MIB