SRX Whitelist for tcp port scan
The whitelist/allowlist feature is only applicable to UDP Flood Screens and TCP SYN Flood Screens. However, for TCP port scans, the whitelist option will not be effective.
root@SRX # set security screen ids-option snfcc-screen tcp port-scan ?
Possible completions:
+ apply-groups Groups from which to inherit configuration data
+ apply-groups-except Don't inherit configuration data from these groups
fin-no-ack Enable Fin bit with no ACK bit ids option
land Enable land attack ids option
> port-scan Configure TCP port scan ids option
> syn-ack-ack-proxy Configure syn-ack-ack proxy ids option
syn-fin Enable SYN and FIN bits set attack ids option
> syn-flood Configure SYN flood ids option
syn-frag Enable SYN fragment ids option
tcp-no-flag Enable TCP packet without flag ids option
> tcp-sweep Configure TCP sweep ids option
winnuke Enable winnuke attack ids option