jnxJsPolicyNumber
1.3.6.1.4.1.2636.3.39.1.4.1.1.1
Integer32
The number of policies (regardless of their current state) present on this system.
2013-07-02
This module defines the mib for policy monitoring. A security policy, which can be configured from the user interface controls the traffic flow from one zone to another zone by defining the kind(s) of traffic permitted from specified IP sources to specified IP destinations at scheduled times. Juniper security device enforce the security policies rules for the transit traffic in terms of which traffic can pass through the firewall, and the actions taken on the traffic as it passes through the firewall.
Download JUNIPER-JS-POLICY-MIB.txt Open JUNIPER-JS-POLICY-MIB.txt in a new tab
| Name | OID |
|---|---|
| jnxJsPolicyTable | 1.3.6.1.4.1.2636.3.39.1.4.1.1.2 |
| jnxJsPolicyStatsTable | 1.3.6.1.4.1.2636.3.39.1.4.1.1.3 |
END OF TOC
1.3.6.1.4.1.2636.3.39.1.4.1.1.1
Integer32
The number of policies (regardless of their current state) present on this system.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.1
Counter64 (0..18446744073709551615)
The number of IPv4 packets allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.2
Counter64 (0..18446744073709551615)
The number of IPv4 bytes allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.3
Gauge32
The rate of IPv4 packets allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.4
Gauge32
The rate of IPv4 bytes allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.5
Counter64 (0..18446744073709551615)
The number of IPv4 packets dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.6
Counter64 (0..18446744073709551615)
The number of IPv4 bytes dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.7
Gauge32
The rate of IPv4 packets dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.8
Gauge32
The rate of IPv4 bytes dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.9
Counter64 (0..18446744073709551615)
The number of IPv4 flows allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.1.10
Gauge32
The rate of IPv4 flows allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.1
Counter64 (0..18446744073709551615)
The number of IPv6 packets allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.2
Counter64 (0..18446744073709551615)
The number of IPv6 bytes allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.3
Gauge32
The rate of IPv6 packets allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.4
Gauge32
The rate of IPv6 bytes allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.5
Counter64 (0..18446744073709551615)
The number of IPv6 packets dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.6
Counter64 (0..18446744073709551615)
The number of IPv6 bytes dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.7
Gauge32
The rate of IPv6 packets dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.8
Gauge32
The rate of IPv6 bytes dropped by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.9
Counter64 (0..18446744073709551615)
The number of IPv6 flows allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.2.10
Gauge32
The rate of IPv6 flows allowed by all policies.
1.3.6.1.4.1.2636.3.39.1.4.1.3.3
INTEGER1 = enabled2 = disabled · Integer32
The configured status of Policy System Wide Statistic Collection.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2
Index: jnxJsPolicyFromZone · jnxJsPolicyToZone · jnxJsPolicyName
The table exposes the security policy entries. Security devices/routers provide a network boundary with a single point of entry and exit point, which allows the screening and directing of traffic through the implementation of access policies. The access policies can permit, deny, encrypt, authenticate, prioirtize, schedule and monitor the traffic flow through the firewall. This table lists entries of policy. The number of policies are given by jnxJsPolicyNumber.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.1
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..63) · OCTET STRING · hint 255a
The attribute displays the from zone name.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.2
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..63) · OCTET STRING · hint 255a
The attribute exposes the to-zone name.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.3
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..63) · OCTET STRING · hint 255a
The name of the policy defined. It consists of up to 256 ascii characters and uniquely identifies the policy entry.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.4
Integer32
The attribute indicates the policy sequence order of the policy within a specific from-zone and to-zone pair. Policies are matched in a sequence where the ordering is specified by this number.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.5
INTEGER1 = permit2 = deny3 = reject · Integer32
The attribute indicates the actions performed when the criteria is matched. The action permit, deny and reject are used configured policies.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.6
DisplayStringRepresents textual information taken from the NVT ASCII character set, as defined in pages 4, 10-11 of RFC 854. To summarize RFC 854, the NVT ASCII repertoire specifies: - the use of character codes 0-127 (decimal) - the graphics characters (32-126) are interpreted as US ASCII - NUL, LF, CR, BEL, BS, HT, VT and FF have the special meanings specified in RFC 854 - the other 25 codes have no standard interpretation - the sequence 'CR LF' means newline - the sequence 'CR NUL' means carriage-return - an 'LF' not preceded by a 'CR' means moving to the same column on the next line. - the sequence 'CR x' for any x other than LF or NUL is illegal. (Note that this also means that a string may end with either 'CR LF' or 'CR NUL', but not with CR.) Any object defined using this syntax may not exceed 255 characters in length. SIZE (0..63) · OCTET STRING · hint 255a
The name of the schedule attached to this policy. Certain schedule has a specified duration and this may effect the status of the policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.7
INTEGER1 = active2 = inactive3 = unavailable · Integer32
The state of this policy: active, inactive, or unavailable. The state can be effected by the scheduler if the scheduler has a specified duration.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.8
INTEGER1 = available2 = unavailable · Integer32
The statistics availability of this policy. The attribute indicates whether the statistics counters are available and are actively updated. If available, there would exists a matching jnxJsPolicyStatsEntry for the policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.9
Integer32
The attribute indicates the threshold value of bytes per second.
1.3.6.1.4.1.2636.3.39.1.4.1.1.2.1.10
Integer32
The attribute indicates the threshold value of kbyte per min.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3
Index: jnxJsPolicyFromZone · jnxJsPolicyToZone · jnxJsPolicyName
The table exposes the security policy statistics entries. These statistics can be enabled and disabled by configuration on a per policy basis.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.1
TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks
The creation timestamp of the policy statistics entry. The timestamp is modified during the creation and deletion of the policy statistics entry. When the timestamp changes, the policy entry statistics is assumed to be a new statistics entry and not associated with previous statistic entry of the same indices.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.2
Counter64 (0..18446744073709551615)
The number of input bytes enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.3
Gauge32
The number of input bytes per second or the rate that enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.4
Counter64 (0..18446744073709551615)
The number of output bytes associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.5
Gauge32
The number of output bytes per second or the rate associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.6
Counter32
The number of input packets enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.7
Gauge32
The number of input packets per second or the input packet rate of the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.8
Counter32
The number of output packets associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.9
Gauge32
The number of output packets per second or the rate associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.10
Counter32
The number of sessions associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.11
Gauge32
The rate of the sessions associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.12
Counter32
The number of sessions associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.13
Counter32
The number of policy lookups performed.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.14
Counter32
The number of alarm counted when the traffic exceeds certain threshold configuration. The node is obsoleted.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.15
Counter64 (0..18446744073709551615)
The number of input bytes in the session initial direction enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.16
Counter64 (0..18446744073709551615)
The number of input bytes in the session reply direction enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.17
Gauge32
The number of input bytes in the session initial direction per second or the rate that enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.18
Gauge32
The number of input bytes in the session reply direction per second or the rate that enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.19
Counter64 (0..18446744073709551615)
The number of output bytes in the session initial direction associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.20
Counter64 (0..18446744073709551615)
The number of output bytes in the session reply direction associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.21
Gauge32
The number of output bytes in the session initial direction per second or the rate associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.22
Gauge32
The number of output bytes in the session reply direction per second or the rate associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.23
Counter32
The number of input packets in the session initial direction enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.24
Counter32
The number of input packets in the session reply direction enters the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.25
Gauge32
The number of input packets in the session initial direction per second or the input packet rate of the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.26
Gauge32
The number of input packets in the session reply direction per second or the input packet rate of the FW through this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.27
Counter32
The number of output packets in the session initial direction associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.28
Counter32
The number of output packets in the session reply direction associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.29
Gauge32
The number of output packets in the session initial direction per second or the rate associated with this policy.
1.3.6.1.4.1.2636.3.39.1.4.1.1.3.1.30
Gauge32
The number of output packets in the session reply direction per second or the rate associated with this policy.