Example: Dropping IP Packets Containing SYN Fragments (CLI)
The following example shows how to configure the syn-frag screen to drop fragmented SYN packets originating from the zone security zone.
To drop IP packets containing SYN fragments:
Configure the syn-frag screen:
user@host# set security screen ids-option syn-frag tcp syn-fragConfigure the zone security zone:
user@host# set security zones security-zone zone screen syn-frag
Related Topics
- Junos OS Feature Support Reference for SRX Series and J Series Devices
Hide Navigation Pane
Show Navigation Pane
Download
SHA1