|
Statistics Summary |
|
Interface
|
Name of the services interface on which the service set is applied.
|
|
Service Set
|
Name of the service set.
|
|
Accept
|
Number of packets accepted by all rules defined in the service set.
|
|
Discard
|
Number of packets discarded by all rules defined in the service set.
|
|
Reject
|
Number of packets rejected by all rules defined in the service set.
|
|
New flows
|
Number of packets matching rules defined in new flows:
- Accept—Number of packets accepted.
- Discards—Number of packets discarded.
- Rejects—Number of packets rejected.
|
|
Existing flows
|
Number of packets matching rules defined in existing flows:
- Accept—Number of packets accepted.
- Discards—Number of packets discarded.
- Rejects—Number of packets rejected.
|
|
Drops
|
Number of packets dropped due to the following match conditions:
- IP Option—Number of packets dropped due to the inspection
of the IP options field of the packet.
- TCP SYN Defense—Number of packets dropped due to the SYN
defender, which prevents denial-of-service (DoS) attacks.
- NAT Ports Exhausted—Number of packets dropped because the
router has no available NAT ports to assign for a given source address.
For more information about these match conditions, see the J-series Services Router Configuration Guide and the JUNOS Services Interfaces Configuration Guide.
|
|
Errors
|
Number of protocol errors detected:
- IP—Number of IPv4 errors (for example, Minimum IP header
length check failures).
- TCP—Number of TCP errors (for example, Source or destination
port number is zero).
- UDP—Number of UDP errors (for example, IP data length
less than minimum UDP header length (8 bytes)).
- ICMP—Number of ICMP errors (for example, Duplicate
ping sequence number).
- Non-IP Packets—Number of errors in packets that are not
IPv4 packets.
- ALG—Number of application-level gateway (ALG) errors.
For a complete list of protocol errors that are counted, see the description
of the show services stateful-firewall statistics command in the JUNOS System Basics and Services Command Reference.
|
| Stateful Firewall |
|
Protocol
|
Protocol used for the specified stateful firewall flow.
|
|
Source IP
|
Source prefix of the stateful firewall flow.
|
|
Source Port
|
Source port number of stateful firewall flow.
|
|
Destination IP
|
Destination prefix of the stateful firewall flow.
|
|
Destination Port
|
Destination port number of the stateful firewall flow.
|
|
Flow State
|
Status of the stateful firewall flow:
-
Drop—Drop all packets in the flow without response.
-
Forward—Forward the packet in the flow without
inspecting it.
-
Reject—Drop all packets in the flow with response.
-
Watch—Inspect packets in the flow.
|
|
Direction
|
Direction of the flow: I (input) or O (output).
|
|
Frames
|
Number of frames in the flow.
|
| IDS Information |
|
Source Address
|
Source address for the event.
|
|
Destination address
|
Destination address for the event.
|
|
Time
|
Total time the information has been in the IDS table.
|
|
Bytes
|
Total number of bytes sent from the source to the destination address,
in thousands (k) or millions (m).
|
|
Packets
|
Total number of packets sent from the source to the destination address,
in thousands (k) or millions (m).
|
|
Flows
|
Total number of flows of packets sent from the source to the destination
address, in thousands (k) or millions (m).
|
|
Anomalies
|
Total number of anomalies in the anomaly table, in thousands (k)
or millions (m).
|
|
Application
|
Configured application, such as FTP or telnet.
|