The following tables list security features that are supported on J-series Services Routers.
Table 37: Zones
Feature |
More Information |
|---|---|
Security zone |
|
Functional zone |
|
For information about the interfaces that are supported on your device, see the JUNOS Software Interfaces and Routing Configuration Guide. |
|
Table 38: Security Policy
Feature |
More Information |
|---|---|
Address books |
|
Policy application sets |
|
Schedulers |
|
Policy applications |
Understanding Internet-Related Predefined Policy Applications |
Internet Control Message Protocol (ICMP) predefined policy application |
|
Internet-related predefined policy applications |
Understanding Internet-Related Predefined Policy Applications |
Microsoft predefined policy applications |
|
Dynamic routing protocols predefined policy applications |
Understanding Dynamic Routing Protocols Predefined Policy Applications |
Streaming video predefined policy applications |
Understanding Streaming Video Predefined Policy Applications |
Sun remote procedure protocol (RPC) predefined policy applications |
|
Security and tunnel predefined policy applications |
Understanding Security and Tunnel Predefined Policy Applications |
IP-related predefined policy applications |
|
Instant messaging predefined policy applications |
Understanding Instant Messaging Predefined Policy Applications |
Management predefined policy applications |
|
Mail predefined policy applications |
|
UNIX predefined policy applications |
|
Miscellaneous predefined policy applications |
|
Custom policy Applications |
|
Policy application timeouts |
|
Policy verification |
Table 39: Firewall Authentication
Feature |
More Information |
|---|---|
Web authentication |
|
Pass-through authentication |
|
Local authentication server |
|
RADIUS authentication server |
|
LDAP authentication server |
|
SecurID authentication server |
Table 40: Infranet Authentication
Feature |
More Information |
|---|---|
JUNOS Enforcers in Unified Access Control (UAC) deployments |
Table 41: Attack Detection and Prevention
Feature |
More Information |
|---|---|
Bad IP option |
|
Block fragment traffic |
|
FIN flag without ACK flag set protection |
|
ICMP flood protection |
|
ICMP fragment protection |
|
Large size ICMP packet protection |
|
Loose source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP record route option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP security option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP address spoof |
|
IP stream option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP strict source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP address sweep |
|
IP timestamp option |
Screen Options for Detecting IP Options Used For Reconnaissance |
Land attack protection |
|
Ping of death attack protection |
|
Port scan |
|
Source IP based session limit |
|
SYN-ACK-ACK proxy protection |
|
SYN and FIN flags set protection |
|
SYN flood protection |
|
SYN fragment protection |
|
Teardrop attack protection |
|
TCP packet without flag set protection |
|
Unknown protocol protection |
|
UDP flood protection |
|
WinNuke attack protection |
Table 42: Network Address Translation
Table 43: Chassis Cluster
Table 44: IPsec
Table 45: PKI
Table 46: ALGs
Table 47: Netscreen Remote
Feature |
More Information |
|---|---|
Netscreen Remote VPN client |
Table 48: IDP Policy
Feature |
More Information |
|---|---|
Intrusion Detection and Prevention (IDP) Policy |
|
Intrusion prevention system (IPS) rulebase |
|
Exempt rulebase |
|
Custom attacks |
|
Differentiated Services code point (DSCP) marking |
Table 49: IDP Signature Database
Feature |
More Information |
|---|---|
IDP signature database |
|
Predefined policy templates |
|
Signature database—manual download |
|
Signature database—automatic download |
|
Signature database version |
Table 50: IDP Application Identification
Feature |
More Information |
|---|---|
Application identification |
|
Service and application bindings |
|
Application system cache |
Table 51: IDP Monitoring and Logging
Feature |
More Information |
|---|---|
IDP logging |
|
IDP monitoring and debugging (SRX 3400 and SRX 3600 only) |
JUNOS Software CLI Reference |
Table 52: IDP SSL Inspectioon
Feature |
More Information |
|---|---|
IDP SSL Inspection |