NETSCREEN-IDS-MIB Table View

Table-centric layout grouping table, row, and column objects.

Tables
3
Rows
3
Columns
74
.1.3.6.1.4.1.3224.3.1.1 · 1 row entry · 31 columns
NetScreen ScreenOS can allow DI protection on each of
NetScreen device's physical interface. This table collects the
DI protection configuration on each physical interface.
nsIdsProtectSetEntry entry .1.3.6.1.4.1.3224.3.1.1.1
Hold the DI setting attribute.
Indexes
nsIdsProtectZoneIdx
Column Syntax OID
nsIdsProtectZoneIdx
unique zone id.
Integer32
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.3224.3.1.1.1.1
nsIdsDetectPingOfDeath
Detect Ping of Death.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.2
nsIdsDetectTearDrop
Detect Tear Drop Attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.3
nsIdsDetectWinNuke
Detect Win Nuke Attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.4
nsIdsFilterIpSrcRoute
Detect Filter IP Source Route Option attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.5
nsIdsDetectPortScan
Detect Port Scan Death attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.6
nsIdsDetectAddrSweep
Detect Address Sweep Attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.7
nsIdsDetectLand
Detect Land Attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.8
nsIdsBlockComponent
Block Java/ActiveX/ZIP/EXE Component.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.9
nsIdsDetectIpSpoof
Detect IP Spoofing attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.10
nsIdsDetectSyn
Detect SYN attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.11
nsIdsDetectIcmpFlood
Detect ICMP Flood attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.12
nsIdsDetectUdpFlood
Detect UDP Flood attack.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.13
nsIdsDetectSynFrag
Detect SYN fragment
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.14
nsIdsDetectTcpNoFlag
Detect TCP without flag set.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.15
nsIdsDetectIpUnknownProt
Detect Unknown protocol IP packet.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.16
nsIdsDetectIpOptBad
Detect IP bad option.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.17
nsIdsDetectIpOptRecord
Detect IP record option.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.18
nsIdsDetectIpOptTimestamp
Detect IP timestamp option.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.19
nsIdsDetectIpOptSCHT
Detect IP security option.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.20
nsIdsDetectIpOptLSR
Detect Loose source route.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.21
nsIdsDetectIpOptSSR
Detect strict source route.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.22
nsIdsDetectIpOptStream
Detect IP stream option.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.23
nsIdsDetectIcmpFrag
Detect ICMP fragment.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.24
nsIdsDetectIcmpLarge
Detect large ICMP packet.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.25
nsIdsDetectTcpSynFin
Detect TCP syn fin both set.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.26
nsIdsDetectTcpFinNoAck
Detect TCP fin set without ack bit set.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.27
nsIdsHttpMalUrl
Detect malicious URL.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.28
nsIdsSessMalNum
Detect malicious session connection.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.29
nsIdsDetectSynAckAck
Detect SYN ACK ACK DoS.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.30
nsIdsDetectIpFrag
Block IP fragment packet.
Enumeration
Enumerated Values:
0disable
1enabled
.1.3.6.1.4.1.3224.3.1.1.1.31
.1.3.6.1.4.1.3224.3.1.2 · 1 row entry · 11 columns
NetScreen ScreenOS can allow DI protection on each of
NetScreen device's physical interface. This table collects the
DI protection configuration on each physical interface.
nsIdsProtectThreshEntry entry .1.3.6.1.4.1.3224.3.1.2.1
Hold the DI setting attribute.
Indexes
nsIdsProtectThreshZoneIdx
Column Syntax OID
nsIdsProtectThreshZoneIdx
unique zone id.
Integer32
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.3224.3.1.2.1.1
nsIdsSynAttackThresh
SYN attack threshold.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.2
nsIdsSynAttackTimeout
SYN attack timeout.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.3
nsIdsSynAttackAlmTh
SYN attack alarm threshold.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.4
nsIdsSynAttackQueSize
SYN attack queue size.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.5
nsIdsSynAttackAgeTime
SYN flood age time.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.6
nsIdsIcmpFloodThresh
ICMP attack alarm threshold.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.7
nsIdsUdpFloodThresh
UDP attack alarm threshold.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.8
nsIdsPortScanThresh
ICMP attack alarm threshold.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.9
nsIdsIpSweepThresh
UDP attack alarm threshold.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.10
nsIdsSynAckAckThres
SYN ack ack alarm threshold.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.1.2.1.11
.1.3.6.1.4.1.3224.3.2 · 1 row entry · 32 columns
The table monitors the intrusion attack attemps amount to
NetScreen Device.
nsIdsAttkMonEntry entry .1.3.6.1.4.1.3224.3.2.1
An entry containing intrusion attack couters.
Indexes
nsIdsAttkMonIfIdx
Column Syntax OID
nsIdsAttkMonIfIdx
unique interface id.
Integer32
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.3224.3.2.1.1
nsIdsAttkMonVsys
according NetScreen's concepts. each interface belongs to one
virtual system. This attribute displays the virtual system name
an interface belongs to.
SNMPv2-SMIInteger32
Textual Convention: SNMPv2-SMIInteger32 Integer32
Type Constraints:
range: -2147483648..2147483647
.1.3.6.1.4.1.3224.3.2.1.2
nsIdsAttkMonSynAttk
sync attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.3
nsIdsAttkMonTearDrop
tear drop attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.4
nsIdsAttkMonSrcRoute
source route option attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.5
nsIdsAttkMonPingDeath
ping of death attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.6
nsIdsAttkMonAddrSpoof
address spoofing attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.7
nsIdsAttkMonLand
land attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.8
nsIdsAttkMonIcmpFlood
ICMP flood attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.9
nsIdsAttkMonUdpFlood
udp flood attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.10
nsIdsAttkMonWinnuke
weired netbios attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.11
nsIdsAttkMonPortScan
port scan attempt attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.12
nsIdsAttkMonIpSweep
address sweep attemp attack packet counter.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.13
nsAttkMonSynFrag
Detect SYN fragment
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.14
nsAttkMonTcpNoFlag
Detect TCP without flag set.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.15
nsAttkMonIpUnknownProt
Detect Unknown protocol IP packet.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.16
nsAttkMonIpOptBad
Detect IP bad option.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.17
nsAttkMonIpOptRecord
Detect IP record option.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.18
nsAttkMonIpOptTimestamp
Detect IP timestamp option.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.19
nsAttkMonIpOptSCHT
Detect IP security option.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.20
nsAttkMonIpOptLSR
Detect Loose source route.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.21
nsAttkMonIpOptSSR
Detect strict source route.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.22
nsAttkMonIpOptStream
Detect IP stream option.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.23
nsAttkMonIcmpFrag
Detect ICMP fragment.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.24
nsAttkMonIcmpLarge
Detect large ICMP packet.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.25
nsAttkMonTcpSynFin
Detect TCP syn fin both set.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.26
nsAttkMonTcpFinNoAck
Detect TCP fin set without ack bit set.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.27
nsAttkMonHttpMalUrl
Detect malicious URL.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.28
nsAttkMonSessMalNum
Detect malicious session connection.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.29
nsAttkMonSynAckAck
Detect SYN ACK ACK attack.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.30
nsAttkMonIpFrag
Block IP fragment packet.
SNMPv2-SMICounter32
Textual Convention: SNMPv2-SMICounter32 Unsigned32
Type Constraints:
range: 0..4294967295
.1.3.6.1.4.1.3224.3.2.1.31
nsIdsAttkMonIfInfo
Internal id assigned to this interface. Stays persistent across resets.
Integer32
Constraints:
range: 0-2147483647
.1.3.6.1.4.1.3224.3.2.1.32