Example: Dropping Packets Using an Unknown Protocol (CLI)

The following example shows how to configure the unknown-protocol screen to block packets with an unknown protocol originating from the zone security zone.

To drop packets that use an unknown protocol:

  1. Configure the unknown-protocol screen:

    user@host# set security screen ids-option unknown-protocol ip unknown-protocol
  2. Configure the zone security zone:

    user@host# set security zones security-zone zone screen unknown-protocol

Related Topics