Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

then (IDS MS-MPC)

date_range 20-Nov-23

Syntax

content_copy zoom_out_map
then {
    aggregation (IDS) {
        destination-prefix prefix-value | destination-prefix-ipv6 prefix-value;
        source-prefix prefix-value | source-prefix-ipv6 prefix-value;
    }
    allow-ip-options {
        any;
        loose-source-route;
        route-record;
        route-alert;
        security;
        stream-id;
        strict-source-route;
        timestamp;
    }
    allow-ipv6-extension-header {
        any;
        ah;
        dstopts;
        esp;
        fragment;
        hop-by-hop;
        mobility;
        routing;
    }
    icmp-fragment-check;
    icmp-large-packet-check;
    land-attack-check (ip-only | ip-port);
    session-limit {
        by-destination {
            by-protocol {
                icmp {
                    maximum number;
                    packets number;
                    rate number;
                }
                tcp {
                    maximum number;
                    packets number;
                    rate number;
                }
                udp {
                    maximum number;
                    packets number;
                    rate number;
                }
            }
            maximum number;
            packets number;
            rate number;
        }
        by-source {
            by-protocol {
                icmp {
                    maximum number;
                    packets number;
                    rate number;
                }
                tcp {
                    maximum number;
                    packets number;
                    rate number;
                }
                udp {
                    maximum number;
                    packets number;
                    rate number;
                }
            }
            maximum number;
            packets number;
            rate number;
        }
    }
    tcp-syn-defense;
    tcp-syn-fragment-check;
    tcp-winnuke-check;
}

Hierarchy Level

content_copy zoom_out_map
[edit services ids rule rule-name term term-name ]

Description

Configure the network attack prevention actions for an IDS rule for a service set on an MS-MPC.

The remaining statements are explained separately. See CLI Explorer.

Required Privilege Level

interface—To view this statement in the configuration.

interface-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 17.1.

footer-navigation