Juniper Networks J-Series manual Monitoring Stateful Firewall Statistics

Models: J-Series

1 332
Download 332 pages 610 b
Page 159
Image 159

Chapter 7: Monitoring the Router and Routing Operations

This section contains the following topics:

Monitoring Stateful Firewall Statistics on page 137

Monitoring Stateful Firewall Filters on page 138

Monitoring Firewall Intrusion Detection Services (IDS) on page 139

Monitoring Stateful Firewall Statistics

To view stateful firewall filter statistics in the J-Web interface, select Monitor>Firewall>Statistics Summary. Alternatively, enter the CLI command show services stateful-firewall statistics.

Table 70 on page 137 summarizes key output fields for stateful firewall filter statistics.

Table 70: Summary of Key Stateful Firewall Statistics Output Fields

Field

Values

Interface

Name of the services interface on which the service set is applied.

Service Set

Name of the service set.

Accept

Number of packets accepted by all rules defined in the service set.

Discard

Number of packets discarded by all rules defined in the service set.

Reject

Number of packets rejected by all rules defined in the service set.

New flows

Number of packets matching rules defined in new flows:

 

Accept—Number of packets accepted.

 

Discards—Number of packets discarded.

 

Rejects—Number of packets rejected.

Existing flows

Number of packets matching rules defined in existing flows:

 

Accept—Number of packets accepted.

 

Discards—Number of packets discarded.

 

Rejects—Number of packets rejected.

Drops

Number of packets dropped due to the following match conditions:

 

IP Option—Number of packets dropped due to the inspection of the IP options field of the

 

packet.

 

TCP SYN Defense—Number of packets dropped due to the SYN defender, which prevents

 

denial-of-service (DoS) attacks.

 

NAT Ports Exhausted—Number of packets dropped because the router has no available NAT

 

ports to assign for a given source address.

 

For more information about these match conditions, see the J-series Services Router Advanced WAN

 

Access Configuration Guide and the JUNOS Services Interfaces Configuration Guide.

Using the Monitoring Tools 137

Page 159
Image 159
Juniper Networks J-Series manual Monitoring Stateful Firewall Statistics