attacks {
custom-attack-groups [attack-group-name];
custom-attacks [attack-name];
dynamic-attack-groups [attack-group-name];
predefined-attack-groups [attack-group-name];
predefined-attacks [attack-name];
}
destination-address ([address-name] | any | any-ipv4 | any-ipv6);
destination-except [address-name];
from-zone (zone-name | any );
source-address ([address-name] | any | any-ipv4 | any-ipv6);
source-except [address-name];
to-zone (zone-name | any);
}
terminal;
then {
action {
class-of-service {
dscp-code-point number;
forwarding-class forwarding-class;
}
(close-client | close-client-and-server | close-server |drop-connection |
drop-packet | ignore-connection | mark-diffserv value | no-action |
recommended);
}
ip-action {
(ip-block | ip-close | ip-notify);
log;
log-create;
refresh-timeout;
target (destination-address | service | source-address | source-zone |
source-zone-address | zone-service);
timeout seconds;
}
notification {
log-attacks {
alert;
}
packet-log {
post-attack number;
post-attack-timeout seconds;
pre-attack number;
}
}
severity (critical | info | major | minor | warning);
}
}
}
}
security-package {
automatic {
download-timeout minutes;
enable;
interval hours;
start-time start-time;
}
Copyright © 2016, Juniper Networks, Inc.84
Getting Started Guide for Branch SRX Series