JUNIPER-LSYS-SECURITYPROFILE-MIB

MIB Reference — IPNetwork Monitor

All MIBsJUNIPER-LSYS-SECURITYPROFILE-MIB

Category: Domain: Security, Vendor: Juniper

Description:

Defines managed objects for logical system security profile resource allocation on Juniper Networks SRX devices.

Imported Objects

From JUNIPER-JS-SMI

jnxLsysSecurityProfileOBJECT-IDENTITY

What Is JUNIPER-LSYS-SECURITYPROFILE-MIB?

JUNIPER-LSYS-SECURITYPROFILE-MIB is a Juniper Networks MIB that manages security profiles for logical systems (LSYS) — the virtualized firewall partitions supported on Juniper SRX Series services gateways used in multi-tenant or departmental security deployments. It exposes configuration and resource-allocation data covering security zones, traffic schedulers, security policies and their word-count/size limits, and stateful-flow resources such as flow gates and flow sessions assigned to each logical system. This makes it valuable for monitoring the operational health and capacity of a shared SRX device: administrators can track how close each logical system is to its configured policy, flow-gate, or session limits, which is a leading indicator of resource exhaustion that could cause dropped connections or policy failures for a given tenant. It builds on Juniper's broader jnx enterprise MIB tree and logical-systems framework, and is typically used alongside other JUNIPER-LSYS-* MIBs that cover interfaces and general LSYS configuration. It is deployed in service-provider and enterprise environments running Juniper SRX firewalls partitioned into multiple logical systems for different customers or departments. Administrators typically perform a JUNIPER-LSYS-SECURITYPROFILE-MIB download alongside the other JUNIPER-LSYS-* modules when setting up SNMP-based capacity monitoring for a multi-tenant SRX deployment.

IPNetwork Monitor allows you to monitor SNMP objects defined in JUNIPER-LSYS-SECURITYPROFILE-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

What Can Be Monitored

  • security zones per logical system
  • traffic scheduler allocation
  • security policy count/word-count usage
  • flow gate count
  • flow session count

Supported Devices

  • Juniper SRX security gateway (logical systems, any generation supporting LSYS)

Monitoring Examples

An administrator would poll jnxLsysSpFlowsess and jnxLsysSpFlowgate per logical system to see current stateful-session and flow-gate counts against their configured ceilings, spotting a tenant approaching its flow-table limit before new connections start getting rejected. Similarly, jnxLsysSpPolicywcnt tracks policy word-count usage against the per-LSYS security-policy resource cap defined via jnxLsysSpPolicy, and jnxLsysSpZone/jnxLsysSpScheduler expose how many security zones and QoS schedulers are allocated to each logical system. This lets an operator detect a misbehaving or overloaded logical system on a shared SRX chassis before it impacts other tenants.

OIDs
OID symbolicOID numericTypeAccessDescription
jnxLsysSpZone1.3.6.1.4.1.2636.3.39.1.17.1
jnxLsysSpScheduler1.3.6.1.4.1.2636.3.39.1.17.2
jnxLsysSpPolicy1.3.6.1.4.1.2636.3.39.1.17.3
jnxLsysSpPolicywcnt1.3.6.1.4.1.2636.3.39.1.17.4
jnxLsysSpFlowgate1.3.6.1.4.1.2636.3.39.1.17.5
jnxLsysSpFlowsess1.3.6.1.4.1.2636.3.39.1.17.6
jnxLsysSpAuthentry1.3.6.1.4.1.2636.3.39.1.17.7
jnxLsysSpNATsrcpool1.3.6.1.4.1.2636.3.39.1.17.8
jnxLsysSpNATdstpool1.3.6.1.4.1.2636.3.39.1.17.9
jnxLsysSpNATsrcpatad1.3.6.1.4.1.2636.3.39.1.17.10
jnxLsysSpNATsrcnopatad1.3.6.1.4.1.2636.3.39.1.17.11
jnxLsysSpNATsrcrule1.3.6.1.4.1.2636.3.39.1.17.12
jnxLsysSpNATdstrule1.3.6.1.4.1.2636.3.39.1.17.13
jnxLsysSpNATstaticrule1.3.6.1.4.1.2636.3.39.1.17.14
jnxLsysSpNATconebind1.3.6.1.4.1.2636.3.39.1.17.15
jnxLsysSpNATpoipnum1.3.6.1.4.1.2636.3.39.1.17.16
jnxLsysSpNATRuleRefPfx1.3.6.1.4.1.2636.3.39.1.17.17
jnxLsysSpCPU1.3.6.1.4.1.2636.3.39.1.17.18

RFC description

Juniper vendor-private MIB for managing logical system security profiles and policy configurations.

Start monitoring Juniper SRX security gateway (logical systems/security profiles) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download JUNIPER-LSYS-SECURITYPROFILE-MIB