Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

term (IDS MS-MPC)

date_range 20-Nov-23

Syntax

content_copy zoom_out_map
term {
    then {
        aggregation (IDS) {
            destination-prefix prefix-value | destination-prefix-ipv6 prefix-value;
            source-prefix prefix-value | source-prefix-ipv6 prefix-value;
        }
        allow-ip-options {
            any;
            loose-source-route;
            route-record;
            route-alert;
            security;
            stream-id;
            strict-source-route;
            timestamp;
        }
        allow-ipv6-extension-header {
            any;
            ah;
            dstopts;
            esp;
            fragment;
            hop-by-hop;
            mobility;
            routing;
        }
        icmp-fragment-check;
        icmp-large-packet-check;
        land-attack-check (ip-only | ip-port);
        session-limit {
            by-destination {
                by-protocol {
                    icmp {
                        maximum number;
                        packets number;
                        rate number;
                    }
                    tcp {
                        maximum number;
                        packets number;
                        rate number;
                    }
                    udp {
                        maximum number;
                        packets number;
                        rate number;
                    }
                }
                maximum number;
                packets number;
                rate number;
            }
            by-source {
                by-protocol {
                    icmp {
                        maximum number;
                        packets number;
                        rate number;
                    }
                    tcp {
                        maximum number;
                        packets number;
                        rate number;
                    }
                    udp {
                        maximum number;
                        packets number;
                        rate number;
                    }
                }
                maximum number;
                packets number;
                rate number;
            }
        }
        tcp-syn-defense;
        tcp-syn-fragment-check;
        tcp-winnuke-check;
    }
}

Hierarchy Level

content_copy zoom_out_map
[edit services ids rule rule-name]

Description

Configure the network attack prevention actions for an IDS rule for a service set on an MS-MPC.

The remaining statements are explained separately. See CLI Explorer.

Required Privilege Level

interface—To view this statement in the configuration.

interface-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 17.1.

footer-navigation