■
Errata and Changes in Documentation for JUNOS Release 10.1 for SRX Series
Services Gateways and J Series Services Routers on page 165
Errata and Changes in Documentation for JUNOS Release 10.1 for SRX Series Services
Gateways and J Series Services Routers
This section lists outstanding issues with the documentation.
Application Layer Gateways (ALGs)
■
The following section has been removed from the
JUNOS Software Security
Configuration Guide
to reflect RPC ALG data structure cleanup: “Display the Sun
RPC Port Mapping Table.”
■
The “Verifying the RPC ALG Tables” section of the
JUNOS Software Security
Configuration Guide
has been renamed to “Verifying the Microsoft RPC ALG
Tables” to reflect RPC ALG data structure cleanup.
■
ALG configuration examples in the
JUNOS Software Security Configuration Guide
incorrectly show policy-based NAT configurations. NAT configurations are now
rule-based.
■
The
JUNOS Software Security Configuration Guide
incorrectly states that ALGs are
not supported in transparent mode on SRX3400, SRX3600, SRX5600, and
SRX5800 devices. The FTP, TFTP, RTSP, and DNS ALGs are supported in
transparent mode on those devices. Other ALGs are not.
Attack Detection and Prevention
The default parameters documented in the firewall/NAT screen configuration options
table in the
JUNOS Software Security Configuration Guide
and the J-Web online Help
do not match the default parameters in the CLI. The correct default parameters are:
tcp {
syn-flood {
alarm-threshold 1024;
attack-threshold 200;
source-threshold 1024;
destination-threshold 2048;
timeout 20;
}
}
[edit security screen ids-option untrust-screen]
Errata and Changes in Documentation for JUNOS Release 10.1 for SRX Series Services Gateways and J Series Services
Routers
■
165
Errata and Changes in Documentation for JUNOS Release 10.1 for SRX Series Services Gateways and J Series Services Routers