destination-threshold
Syntax
destination-threshold number;
Hierarchy Level
[edit security screen ids-option screen-name tcp syn-flood]
Description
Specify the number of SYN segments received per second for a single destination IP address before the device begins dropping connection requests to that destination. If a protected host runs multiple services, you might want to set a threshold based only on the destination IP address, regardless of the destination port number.
Options
number
—Number of SYN segments received per second before
the device begins dropping connection requests.
Range: 4 through 1,000,000 per second
Default: 4000 per second
Required Privilege Level
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.
Release Information
Statement modified in Junos OS Release 9.2.