All MIBs › JUNIPER-JS-SCREENING-MIB › jnxJsScreenTcpSweepThresh
jnxJsScreenTcpSweepThresh
Module: JUNIPER-JS-SCREENING-MIB
OID (symbolic): JUNIPER-JS-SCREENING-MIB::jnxJsScreenTcpSweepThresh
OID (numeric): 1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.1
Node type: OBJECT-TYPE
Type: Integer32
Access: read-only
Description: The TCP sweep threshold interval is in microseconds. The default threshold value is 5000. The valid threshold range is 1000-1000000.
By using the default settings, if a remote host initiates TCP connection to 10 addresses in 0.005 seconds(5000 microseconds), the security device flags this as an TCP sweep attack, and rejects all further new TCP connections initiated from that host for the remainder of the specified threshold time period. This attribute holds the TCP sweep attack threshold.
What is jnxJsScreenTcpSweepThresh?
This read-only value reports the configured TCP-sweep detection interval in microseconds (default 5000, valid range 1000-1000000): a source initiating TCP connections to 10 addresses within this interval triggers the sweep defense, which then rejects further new TCP connections from that source for the timeout period. An admin reads this to understand how aggressive a horizontal TCP scan has to be before the zone's sweep protection kicks in.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.1 snmpwalk -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenTcpSweepThresh
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.1.1 snmpget -v2c -c public <target> JUNIPER-JS-SCREENING-MIB::jnxJsScreenTcpSweepThresh.1
Start monitoring Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the JUNIPER-JS-SCREENING-MIB::jnxJsScreenTcpSweepThresh OID value, configure state conditions and alerts, and monitor any Juniper SRX/J-series security appliance (DoS/DDoS screen defenses) from a single console.
OID Breakdown
Upper-level ancestors (11 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.2636 | juniperMIB | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3 | jnxMibs | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39 | jnxJsMibRoot | JUNIPER-SMI |
| 1.3.6.1.4.1.2636.3.39.1 | jnxJsSecurity | JUNIPER-JS-SMI |
| 1.3.6.1.4.1.2636.3.39.1.8 | jnxJsScreening | JUNIPER-JS-SMI |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.2636.3.39.1.8.1 | jnxJsScreenMIB | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1 | jnxJsScreenObjects | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.3 | jnxJsScreenSweepTable | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1 | jnxJsScreenSweepEntry | JUNIPER-JS-SCREENING-MIB |
| 1.3.6.1.4.1.2636.3.39.1.8.1.1.3.1.1 | jnxJsScreenTcpSweepThresh | JUNIPER-JS-SCREENING-MIB |