The following tables list security features that are supported on SRX3400, SRX3600, SRX5600, and SRX5800 Services Gateways.
Table 32: ALGs
Feature |
More Information |
|---|---|
FTP Application Layer Gateway (ALG) |
|
Trivial File Transfer Protocol (TFTP) ALG |
Table 33: Attack Detection and Prevention
Feature |
More Information |
|---|---|
Bad IP option |
|
Block fragment traffic |
|
FIN flag without ACK flag set protection |
|
ICMP flood protection |
|
ICMP fragment protection |
|
Large size ICMP packet protection |
|
Loose source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP record route option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP security option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP address spoof |
|
IP stream option |
Screen Options for Detecting IP Options Used For Reconnaissance |
IP strict source route option |
Blocking Packets with Either a Loose or Strict Source Route Option Set |
IP address sweep |
|
IP timestamp option |
Screen Options for Detecting IP Options Used For Reconnaissance |
Land attack protection |
|
Ping of death attack protection |
|
Port scan |
|
Source IP based session limit |
|
SYN-ACK-ACK proxy protection |
|
SYN and FIN flags set protection |
|
SYN flood protection |
|
SYN fragment protection |
|
Teardrop attack protection |
|
TCP packet without flag set protection |
|
Unknown protocol protection |
|
UDP flood protection |
|
WinNuke attack protection |
Table 34: Chassis Cluster
Table 35: Firewall Authentication
Feature |
More Information |
|---|---|
Web authentication |
|
Pass-through authentication |
|
Local authentication server |
|
RADIUS authentication server |
|
LDAP authentication server |
|
SecurID authentication server |
Table 36: Flow-based and Packet-based Procesing
Feature |
More Information |
|---|---|
Combo-mode support (on SRX5600 and SRX5800—single SPC only) |
|
Flow-based processing |
|
Packet-based processing |
|
Datapath Debugging (SRX5600 and SRX5800 only) |
Table 37: Infranet Authentication
Feature |
More Information |
|---|---|
JUNOS Enforcers in Unified Access Control (UAC) deployments |
Table 38: Intrusion Detection and Prevention (IDP)
Feature |
More Information |
|---|---|
IDP Policy |
|
Intrusion prevention system (IPS) rulebase |
|
Differentiated Services code point (DSCP) marking |
|
IDP signature database |
|
Application identification |
|
IDP logging |
|
IDP monitoring and debugging |
JUNOS Software CLI Reference |
IDP SSL Inspection |
|
Performance and Capacity Tuning for IDP |
|
Understanding Protocol Decoders |
|
Multiple IDP Detector Support |
Table 39: IPsec
Table 40: Network Address Translation (NAT)
Table 41: PKI
Table 42: Security Policy
Feature |
More Information |
|---|---|
Address books |
|
Policy application sets |
|
Schedulers |
|
Policy applications |
Understanding Internet-Related Predefined Policy Applications |
Internet Control Message Protocol (ICMP) predefined policy application |
|
Internet-related predefined policy applications |
Understanding Internet-Related Predefined Policy Applications |
Microsoft predefined policy applications |
|
Dynamic routing protocols predefined policy applications |
Understanding Dynamic Routing Protocols Predefined Policy Applications |
Streaming video predefined policy applications |
Understanding Streaming Video Predefined Policy Applications |
Sun remote procedure protocol (RPC) predefined policy applications |
|
Security and tunnel predefined policy applications |
Understanding Security and Tunnel Predefined Policy Applications |
IP-related predefined policy applications |
|
Instant messaging predefined policy applications |
Understanding Instant Messaging Predefined Policy Applications |
Management predefined policy applications |
|
Mail predefined policy applications |
|
UNIX predefined policy applications |
|
Miscellaneous predefined policy applications |
|
Custom policy Applications |
|
Policy application timeouts |
|
Policy verification (SRX5600 and SRX5800 only) |
Table 43: Session Logging
Feature |
More Information |
|---|---|
Getting information about sessions |
|
Session logging with NAT information |
Table 44: Zones
Feature |
More Information |
|---|---|
Security zone |
|
Functional zone |
|
For information about the interfaces that are supported on your device, see the JUNOS Software Interfaces and Routing Configuration Guide. |
|