JUNIPER-JS-SCREENING-MIB :: jnxJsScreenMonSynFrag

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsJUNIPER-JS-SCREENING-MIBjnxJsScreenMonSynFrag

jnxJsScreenMonSynFrag

Module: JUNIPER-JS-SCREENING-MIB

OID (symbolic): JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynFrag

OID (numeric): 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.14

Node type: OBJECT-TYPE

Type: Counter64

Access: read-only

Description: IP encapsulates a TCP SYN segment in the IP packet that initiates a TCP connection. The purpose is to initiate a connection and to invoke a SYN/ACK segment response. The SYN segment typically does not contain any data since the IP packet is small and there is no legitimate reason for it to be fragmented. A fragmented SYN packet is anomalous and is suspectful. To be cautious, it might be helpful to block such these fragments from entering the protected network.

When the syn fragmentation check is enable, the security device detects and drops the packets when the IP header indicates that the packet has been fragmented while the SYN flag is set in the TCP header.

This attributes records the detection of the SYN fragments.

What is jnxJsScreenMonSynFrag?

This read-only counter tallies SYN-fragment attack packets caught in this zone - a TCP SYN segment that has been fragmented despite having no legitimate reason to be, an anomaly the device treats as suspicious and drops. An admin seeing this counter rise knows fragmented, likely evasive, connection-initiation packets are being blocked in the zone.

Examples

Walk all instances (SNMPv2c):

snmpwalk -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.14
snmpwalk -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynFrag

Get a specific instance (index 1):

snmpget -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.14.1
snmpget -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynFrag.1

Start monitoring Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the JUNIPER-JS-SCREENING-MIB::jnxJsScreenMonSynFrag OID value, configure state conditions and alerts, and monitor any Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) from a single console.

OID Breakdown

Upper-level ancestors (11 from the standard OID tree / other modules)
Numeric OIDNameModule
1isoLANART-AGENT
1.3orgAirPair-MIB
1.3.6dodAirPair-MIB
1.3.6.1internetAirPair-MIB
1.3.6.1.4privateAirPair-MIB
1.3.6.1.4.1enterprisesAirPair-MIB
1.3.6.1.4.1.2636juniperMIBJUNIPER-SMI
1.3.6.1.4.1.2636.3jnxMibsJUNIPER-SMI
1.3.6.1.4.1.2636.3.39jnxJsMibRootJUNIPER-SMI
1.3.6.1.4.1.2636.3.39.1jnxJsSecurityJUNIPER-JS-SMI
1.3.6.1.4.1.2636.3.39.1.8jnxJsScreeningJUNIPER-JS-SMI
Numeric OIDNameModule
1.3.6.1.4.1.2636.3.39.1.8.1jnxJsScreenMIBJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1jnxJsScreenObjectsJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1.1jnxJsScreenMonTableJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1jnxJsScreenMonEntryJUNIPER-JS-SCREENING-MIB
1.3.6.1.4.1.2636.3.39.1.8.1.1.1.1.14jnxJsScreenMonSynFragJUNIPER-JS-SCREENING-MIB