- show services stateful-firewall statistics
- <brief | detail | extensive | summary>
- <application-protocol protocol>
- <interface interface-name>
- <service-set service-set>
Command introduced before JUNOS Release 7.4.
Display stateful firewall statistics.
none — Display standard information about all stateful firewall statistics.
brief | detail | extensive | summary — (Optional) Display the specified level of output.
application-protocol protocol — (Optional) Display stateful firewall statistics for one of the following application protocols:
interface interface-name — (Optional) Display information about a particular interface. On M Series and T Series routers, the interface-name can be sp-fpc/pic/port or rspnumber. On the J Series routers, the interface-name is sp-pim/0/port.
service-set service-set — (Optional) Display information about a particular service set.
view
clear services stateful-firewall statistics
Table 286 lists the output fields for the show services stateful-firewall statistics command. Output fields are listed in the approximate order in which they appear.
Table 286: show services stateful-firewall statistics Output Fields
show services stateful-firewall statistics extensive
user@host> show services stateful-firewall statistics
extensive Interface: sp-1/3/0
Service set: interface-svc-set
New flows:
Accept: 907, Discard: 0, Reject: 0
Existing flows:
Accept: 3535, Discard: 0, Reject: 0
Drops:
IP option: 0, TCP SYN defense: 0
NAT ports exhausted: 0
Errors:
IP: 0, TCP: 0
UDP: 0, ICMP: 0
Non-IP packets: 0, ALG: 0
IP errors:
IP packet length inconsistencies: 0
Minimum IP header length check failures: 0
Reassembled packet exceeds maximum IP length: 0
Illegal source address: 0
Illegal destination address: 0
TTL zero errors: 0, IP protocol number 0 or 255: 0
Land attack: 0, Smurf attack: 0
Non IP packets: 0, IP option: 0
Non-IPv4 packets: 0, Bad checksum: 0
Illegal IP fragment length: 0
IP fragment overlap: 0
IP fragment reassembly timeout: 0
TCP errors:
TCP header length inconsistencies: 0
Source or destination port number is zero: 0
Illegal sequence number, flags combination: 0
SYN attack (multiple SYNs seen for the same flow): 0
First packet not SYN: 0
TCP port scan (Handshake, RST seen from server for SYN): 0
Bad SYN cookie response: 0
UDP errors:
IP data length less than minimum UDP header length (8 bytes): 0
Source or destination port is zero: 0
UDP port scan (ICMP error seen for UDP flow): 0
ICMP errors:
IP data length less than minimum ICMP header length (8 bytes): 0
ICMP error length inconsistencies: 0
Ping duplicate sequence number: 0
Ping mismatched sequence number: 0
ALG drops:
BOOTP: 0, DCE-RPC: 0, DCE-RPC portmap: 0
DNS: 0, Exec: 0, FTP: 0
H323: 0, ICMP: 0, IIOP: 0
Login: 0, Netbios: 0, Netshow: 0
Realaudio: 0, RPC: 0, RPC portmap: 0
RTSP: 0, Shell: 0
SNMP: 0, Sqlnet: 0, TFTP: 0
Traceroute: 0