Description

SRX Whitelist for tcp port scan

Solution

The whitelist/allowlist feature is only applicable to UDP Flood Screens and TCP SYN Flood Screens. However, for TCP port scans, the whitelist option will not be effective.

 

root@SRX # set security screen ids-option snfcc-screen tcp port-scan  ?

Possible completions:

+ apply-groups    Groups from which to inherit configuration data

+ apply-groups-except Don't inherit configuration data from these groups

 fin-no-ack     Enable Fin bit with no ACK bit ids option

 land        Enable land attack ids option

> port-scan      Configure TCP port scan ids option

> syn-ack-ack-proxy  Configure syn-ack-ack proxy ids option

 syn-fin       Enable SYN and FIN bits set attack ids option

> syn-flood      Configure SYN flood ids option

 syn-frag      Enable SYN fragment ids option

 tcp-no-flag     Enable TCP packet without flag ids option

> tcp-sweep      Configure TCP sweep ids option

 winnuke       Enable winnuke attack ids option

Modification History

2024-09-12 : Article Created

Related Information

https://www.juniper.net/documentation/us/en/software/junos/cli-reference/topics/ref/statement/security-edit-white-list.html