ip (Signature Attack)
Syntax
ip {destination {match (equal | greater-than
| less-than | not-equal);value
hostname ;}identification {match (equal | greater-than
| less-than | not-equal);value
identification-value ;}ip-flags {(df | no-df);(mf | no-mf);(rb | no-rb);}protocol {match (equal | greater-than
| less-than | not-equal);value
transport-layer-protocol-id
;}source {match (equal | greater-than
| less-than | not-equal);value
hostname ;}tos {match (equal | greater-than
| less-than | not-equal);value
type-of-service-in-decimal
;}total-length {match (equal | greater-than
| less-than | not-equal);value
total-length-of-ip-datagram
;}ttl {match (equal | greater-than
| less-than | not-equal);value
time-to-live ;}}
Hierarchy Level
[edit security idp custom-attack attack-name attack-type signature protocol]
Release Information
Statement introduced in Release 9.3 of Junos OS.
Description
Allow IDP to match the IP header information for the signature attack.
Options
The remaining statements are explained separately.
Usage Guidelines
For configuration instructions and examples, see the Junos OS Security Configuration Guide.
Required Privilege Level
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.
Hide Navigation Pane
Show Navigation Pane
Download
SHA1