udp {
checksum-validate {
match (equal | greater-than | less-than | not-equal);
value checksum-value;
}
data-length {
match (equal | greater-than | less-than | not-equal);
value data-length;
}
destination-port {
match (equal | greater-than | less-than | not-equal);
value destination-port;
}
source-port {
match (equal | greater-than | less-than | not-equal);
value source-port;
}
}
}
protocol-binding {
application application-name;
icmp;
icmpv6;
ip {
protocol-number transport-layer-protocol-number;
}
ipv6 {
protocol-number transport-layer-protocol-number;
}
rpc {
program-number rpc-program-number;
}
tcp {
minimum-port port-number <maximum-port port-number>;
}
udp {
minimum-port port-number <maximum-port port-number>;
}
}
regexp regular-expression;
shellcode (all | intel | no-shellcode | sparc);
}
}
recommended-action (close | close-client | close-server | drop | drop-packet | ignore
| none);
severity (critical | info | major | minor | warning);
time-binding {
count count-value;
scope (destination | peer | source);
}
}
custom-attack-group custom-attack-group-name {
group-members [attack-or-attack-group-name];
}
dynamic-attack-group dynamic-attack-group-name {
filters {
Copyright © 2016, Juniper Networks, Inc.82
Getting Started Guide for Branch SRX Series