Configuring UDP Bomb Attack Screen
If the UDP length specified is less than the IP length specified then the malformed packet type is associated with a denial-of-service attempt. By default, NFX drops these packets.
To enable detection of UDP bomb attack:
set security screen ids-option udp-bomb-attack udp flood set security zones security-zone trust screen udp-bomb-attack set security zones security-zone trust host-inbound-traffic system-services all set security zones security-zone trust host-inbound-traffic protocols all set security zones security-zone trust interfaces ge-1/0/1.0