Juniper Networks J-Series manual Monitoring Stateful Firewall Filters, Bytes

Models: J-Series

1 332
Download 332 pages 610 b
Page 160
Image 160

J-series™ Services Router Administration Guide

Table 70: Summary of Key Stateful Firewall Statistics Output Fields (continued)

Field

Values

Errors

Number of protocol errors detected:

 

IP—Number of IPv4 errors (for example, Minimum IP header length check failures).

 

TCP—Number of TCP errors (for example, Source or destination port number is zero).

 

UDP—Number of UDP errors (for example, IP data length less than minimum UDP header length

 

(8 bytes)).

 

ICMP—Number of ICMP errors (for example, Duplicate ping sequence number).

 

Non-IP Packets—Number of errors in packets that are not IPv4 packets.

 

ALG—Number of application-level gateway (ALG) errors.

 

For a complete list of protocol errors that are counted, see the description of the show services

 

stateful-firewall statistics command in the JUNOS System Basics and Services Command Reference.

Monitoring Stateful Firewall Filters

To view stateful firewall filter information in the J-Web interface, select Monitor>Firewall>Stateful Firewall. To display stateful firewall filter information for a particular address prefix, port, or other characteristic, type or select information in one or more of the Narrow Search boxes, and click OK.

Alternatively, enter the following CLI show commands:

show services stateful-firewall conversations

show services stateful-firewall flows

Table 71 on page 138 summarizes key output fields for stateful firewall filters.

Table 71: Summary of Key Stateful Firewall Filters Output Fields

Field

Values

Protocol

Protocol used for the specified stateful firewall flow.

Source IP

Source prefix of the stateful firewall flow.

Source Port

Source port number of stateful firewall flow.

Destination IP

Destination prefix of the stateful firewall flow.

Destination Port

Destination port number of the stateful firewall flow.

Flow State

Status of the stateful firewall flow:

 

Drop—Drop all packets in the flow without response.

 

Forward—Forward the packet in the flow without inspecting it.

 

Reject—Drop all packets in the flow with response.

 

Watch—Inspect packets in the flow.

138Using the Monitoring Tools

Page 160
Image 160
Juniper Networks J-Series Monitoring Stateful Firewall Filters, Summary of Key Stateful Firewall Filters Output Fields