- show security screen statistics
- (zone
zone-name | interface interface-name)
- <node ( node-id | all | local
| primary)>
Command introduced in Release 8.5 of JUNOS software; node options added in Release 9.0 of JUNOS software.
Display intrusion detection system (IDS) security screen statistics.
This command is supported on J-series and SRX-series devices.
none—Display IDS security for all zones and interface.
zone zone-name —(Optional) Display screen statistics for this security zone.
interface interface-name—(Optional) Display screen statistics for this interface.
node—(Optional) For chassis cluster configurations, display security screen statistics on a specific node.
view
clear security screen statistics
clear security screen statistics interface
clear security screen statistics zone
Table 93 lists the output fields for the show security screen statistics command. Output fields are listed in the approximate order in which they appear.
Table 93: show security screen statistics Output Fields
user@host> show
security screen statistics zone scrzone
Screen statistics: IDS attack type Statistics ICMP flood 0 UDP flood 0 TCP winnuke 0 TCP port scan 91 ICMP address sweep 0 IP tear drop 0 TCP SYN flood 0 IP spoofing 0 ICMP ping of death 0 IP source route option 0 TCP land attack 0 TCP SYN fragment 0 TCP no flag 0 IP unknown protocol 0 IP bad options 0 IP record route option 0 IP timestamp option 0 IP security option 0 IP loose source route option 0 IP strict source route option 0 IP stream option 0 ICMP fragment 0 ICMP large packet 0 TCP SYN FIN 0 TCP FIN no ACK 0 Source session limit 0 TCP SYN-ACK-ACK proxy 0 IP block fragment 0 Destination session limit 0
user@host> show
security screen statistics interface ge-0/0/3
Screen statistics: IDS attack type Statistics ICMP flood 0 UDP flood 0 TCP winnuke 0 TCP port scan 91 ICMP address sweep 0 IP tear drop 0 TCP SYN flood 0 IP spoofing 0 ICMP ping of death 0 IP source route option 0 TCP land attack 0 TCP SYN fragment 0 TCP no flag 0 IP unknown protocol 0 IP bad options 0 IP record route option 0 IP timestamp option 0 IP security option 0 IP loose source route option 0 IP strict source route option 0 IP stream option 0 ICMP fragment 0 ICMP large packet 0 TCP SYN FIN 0 TCP FIN no ACK 0 Source session limit 0 TCP SYN-ACK-ACK proxy 0 IP block fragment 0 Destination session limit 0
user@host> show
security screen statistics interface ge-0/0/1 node primary
node0: -------------------------------------------------------------------------- Screen statistics: IDS attack type Statistics ICMP flood 1 UDP flood 1 TCP winnuke 1 TCP port scan 1 ICMP address sweep 1 IP tear drop 1 TCP SYN flood 1 IP spoofing 1 ICMP ping of death 1 IP source route option 1 TCP land attack 1 TCP SYN fragment 1 TCP no flag 1 IP unknown protocol 1 IP bad options 1 IP record route option 1 IP timestamp option 1 IP security option 1 IP loose source route option 1 IP strict source route option 1 IP stream option 1 ICMP fragment 1 ICMP large packet 1 TCP SYN FIN 1 TCP FIN no ACK 1 Source session limit 1 TCP SYN-ACK-ACK proxy 1 IP block fragment 1 Destination session limit 1