show ddos-protection protocols
语法
show ddos-protection protocols <protocol-group (aggregate | packet-type)>
描述
显示支持的协议组或单个数据包类型的控制平面 DDoS 防护配置和统计信息。
选项
none | 显示所有协议组中所有数据包类型的信息。 |
aggregate |
(可选)显示聚合监管器的控制平面 DDoS 保护信息。该 |
packet-type | (可选)显示指定协议组中指定数据包类型的控制平面 DDoS 防护信息。可用的数据包类型因协议组而异,只有某些协议组可以具有适用于单个数据包类型的监管器。 |
protocol-group | (可选)显示协议组的控制平面 DDoS 防护信息。 |
有关可与此命令配合使用的不同设备上的可用protocol-grouppacket-type选项和选项的列表,请参阅以下配置语句,这些选项与用于更改默认监管器配置的受支持选项相同:
有关除 PTX 系列路由器以外的路由设备,请参阅协议 (DDoS)。
有关 PTX 系列路由器和 QFX 系列交换机,请参阅协议 (DDoS)(ACX 系列、PTX 系列和 QFX 系列)。
所需权限级别
视图
输出字段
表 1 列出了命令 show ddos-protection protocols
的输出字段。输出字段按其出现的大致顺序列出。
字段名称 |
字段说明 |
---|---|
|
数据包类型数 |
|
监管器值已从默认值修改的数据包数。 |
|
接收的流量数。 |
|
当前违反流带宽限制的流数。 |
|
流检测跟踪为罪魁祸首流的活动流数。 |
|
已检测到的罪魁祸首流总数,包括已恢复或超时的流。 |
|
协议组的名称。 |
|
协议组中数据包类型的名称。 |
|
带宽监管器值;在声明冲突之前每秒允许的数据包数。 |
|
突发监管器值;在声明冲突之前突发中允许的最大数据包数。 |
|
在发生流量拥塞时允许更重要的流量通过的各个数据包监管器的数据包类型的优先级: |
|
自上次违规以来必须经过的时间,然后流量才被视为已从攻击中恢复。计时器过期时将生成通知。 |
|
监管器的状态:
对于层次结构级别的所有 |
|
绕过聚合配置的状态:
此字段仅对单个监管器显示。 |
|
路由器上配置的流状态检测:
|
|
为路由器收集的以下信息:
|
|
为路由引擎收集的以下信息:
|
|
为指定插槽中的卡收集的以下信息:
注意:
|
|
绕过聚合配置的状态:
破折号表示旁路聚合配置不可用;这仅适用于聚合监管器。 |
|
指示配置是否已从任何线卡的默认值更改。
|
|
数据包类型的可疑流量检测操作模式:始终开启 ( |
|
带宽监管器值;在声明冲突之前每秒允许的数据包数。 |
|
流操作模式、流控制模式以及每个流量流聚合级别数据包类型流量的流带宽:用户 ( |
|
数据包类型的可疑流量自动记录状态:开 ( |
|
数据包类型的罪魁祸首流超时行为的状态:在配置的超时期限内抑制或监视流 ( |
示例输出
- 显示 DDoS 防护协议
- 显示 DDoS 防护协议(禁用流检测的特定数据包类型)
- 显示 DDoS 防护协议(启用流量检测且自动的特定数据包类型)
- 显示 DDoS 防护协议(带宽违规的特定数据包类型)
- 显示 DDoS 防护协议(ARP 广播)
- 显示 DDoS 防护协议(ARP 单播)
- 显示 DDoS 防护协议 IP 选项参数
显示 DDoS 防护协议
user@host> show ddos-protection protocols Packet types: 190, Modified: 0, Received traffic: 12, Currently violated: 3 Currently tracked flows: 0, Total detected flows: 0 * = User configured value Protocol Group: IPv4-Unclassified Packet type: aggregate (Aggregate for unclassified host-bound IPv4 traffic) Aggregate policer configuration: Bandwidth: 2000 pps Burst: 10000 packets Recover time: 300 seconds Enabled: Yes Flow detection configuration: Detection mode: Automatic Detect time: 3 seconds Log flows: No Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 2000 pps System-wide information: Aggregate bandwidth is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Routing Engine information: Bandwidth: 2000 pps, Burst: 10000 packets, enabled Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by individual policers: 0 FPC slot 1 information: Bandwidth: 100% (2000 pps), Burst: 100% (10000 packets), enabled Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by individual policers: 0 Dropped by flow suppression: 0 … Protocol Group: PPPoE Packet type: aggregate (Aggregate for all PPPoE control traffic) Aggregate policer configuration: Bandwidth: 2000 pps Burst: 2000 packets Recover time: 300 seconds Enabled: Yes Flow detection configuration: Detection mode: Automatic Detect time: 3 seconds Log flows: No Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 2000 pps System-wide information: Aggregate bandwidth is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Routing Engine information: Bandwidth: 2000 pps, Burst: 2000 packets, enabled Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by individual policers: 0 FPC slot 1 information: Bandwidth: 100% (2000 pps), Burst: 100% (2000 packets), enabled Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by individual policers: 0 Dropped by flow suppression: 0 Packet type: padi (PPPoE PADI) Individual policer configuration: Bandwidth: 500 pps Burst: 500 packets Priority: Low Recover time: 300 seconds Enabled: Yes Bypass aggregate: No Flow detection configuration: Detection mode: Automatic Detect time: 3 seconds Log flows: No Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 500 pps System-wide information: Bandwidth is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Routing Engine information: Bandwidth: 500 pps, Burst: 500 packets, enabled Policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by aggregate policer: 0 FPC slot 1 information: Bandwidth: 100% (500 pps), Burst: 100% (500 packets), enabled Policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by aggregate policer: 0 Dropped by flow suppression: 0 ...
显示 DDoS 防护协议(禁用流检测的特定数据包类型)
user@host> show ddos-protection protocols pppoe padi Currently tracked flows: 0, Total detected flows: 0 * = User configured value Protocol Group: PPPoE Packet type: padi (PPPoE PADI) Individual policer configuration: Bandwidth: 500 pps Burst: 500 packets Priority: Low Recover time: 300 seconds Enabled: Yes Bypass aggregate: No Flow detection configuration: Detection mode: Off* Detect time: 3 seconds Log flows: No Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 500 pps System-wide information: Bandwidth is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Routing Engine information: Bandwidth: 500 pps, Burst: 500 packets, enabled Policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by aggregate policer: 0 FPC slot 1 information: Bandwidth: 100% (500 pps), Burst: 100% (500 packets), enabled Policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by aggregate policer: 0 Dropped by flow suppression: 0
显示 DDoS 防护协议(启用流量检测且自动的特定数据包类型)
user@host> show ddos-protection protocols pppoe padi Currently tracked flows: 0, Total detected flows: 0 * = User configured value Protocol Group: PPPoE Packet type: padi (PPPoE PADI) Individual policer configuration: Bandwidth: 500 pps Burst: 500 packets Priority: Low Recover time: 300 seconds Enabled: Yes Bypass aggregate: No Flow detection configuration: Detection mode: Automatic Detect time: 3 seconds Log flows: No Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 500 pps System-wide information: Bandwidth is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Routing Engine information: Bandwidth: 500 pps, Burst: 500 packets, enabled Policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by aggregate policer: 0 FPC slot 1 information: Bandwidth: 100% (500 pps), Burst: 100% (500 packets), enabled Policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by aggregate policer: 0 Dropped by flow suppression: 0
显示 DDoS 防护协议(带宽违规的特定数据包类型)
user@host> show ddos-protection protocols bfd Packet types: 1, Modified: 0, Received traffic: 1, Currently violated: 1 Currently tracked flows: 1, Total detected flows: 1 * = User configured value Protocol Group: BFD Packet type: aggregate (Aggregate for all bfd traffic) Aggregate policer configuration: Bandwidth: 20000 pps Burst: 20000 packets Recover time: 300 seconds Enabled: Yes Flow detection configuration: Detection mode: Automatic Detect time: 3 seconds Log flows: No Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 20000 pps System-wide information: Aggregate bandwidth is being violated! No. of FPCs currently receiving excess traffic: 1 No. of FPCs that have received excess traffic: 1 Violation first detected at: 2012-10-24 23:40:20 EDT Violation last seen at: 2012-10-25 10:25:48 EDT Duration of violation: 10:45:28 Number of violations: 1 Received: 1173471731 Arrival rate: 30304 pps Dropped: 399135607 Max arrival rate: 30331 pps Flow counts: Aggregation level Current Total detected Subscriber 1 1 Total 1 1 Routing Engine information: Bandwidth: 20000 pps, Burst: 20000 packets, enabled Aggregate policer is never violated Received: 366831604 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 9522 pps Dropped by individual policers: 0 FPC slot 1 information: Bandwidth: 100% (20000 pps), Burst: 100% (20000 packets), enabled Aggregate policer is currently being violated! Violation first detected at: 2012-10-24 23:40:21 EDT Violation last seen at: 2012-10-25 10:25:48 EDT Duration of violation: 10:45:27 Number of violations: 1 Received: 1173471731 Arrival rate: 30304 pps Dropped: 399135607 Max arrival rate: 30331 pps Dropped by individual policers: 0 Dropped by aggregate policer: 398854530 Dropped by flow suppression: 281077 Flow counts: Aggregation level Current Total detected State Subscriber 1 1 Active Logical-interface 0 0 Active Physical-interface 0 0 Active Total 1 1
显示 DDoS 防护协议(ARP 广播)
user@host> show ddos-protection protocols arp bcast Currently tracked flows: 0, Total detected flows: 0 * = User configured value Protocol Group: ARP Packet type: bcast (Arp broadcast) Aggregate policer configuration: Bandwidth: 10000 pps Burst: 10000 packets Priority: Low Recover time: 300 seconds Enabled: Yes Flow detection configuration: Flow detection system is off Detection mode: Automatic Detect time: 3 seconds Log flows: Yes Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 10000 pps System-wide information: Aggregate bandwidth is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Routing Engine information: Bandwidth: 10000 pps, Burst: 10000 packets, enabled Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by individual policers: 0 FPC slot 2 information: Bandwidth: 100% (10000 pps), Burst: 100% (10000 packets), enabled Hostbound queue 2 Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by individual policers: 0 Dropped by flow suppression: 0
显示 DDoS 防护协议(ARP 单播)
user@host> show ddos-protection protocols arp ucast Currently tracked flows: 0, Total detected flows: 0 * = User configured value Protocol Group: ARP Packet type: ucast (Arp unicast) Aggregate policer configuration: Bandwidth: 10000 pps Burst: 10000 packets Priority: High Recover time: 300 seconds Enabled: Yes Bypass aggregate: No Flow detection configuration: Flow detection system is off Detection mode: Automatic Detect time: 3 seconds Log flows: Yes Recover time: 60 seconds Timeout flows: No Timeout time: 300 seconds Flow aggregation level configuration: Aggregation level Detection mode Control mode Flow rate Subscriber Automatic Drop 10 pps Logical interface Automatic Drop 10 pps Physical interface Automatic Drop 10000 pps System-wide information: Aggregate bandwidth is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Routing Engine information: Bandwidth: 10000 pps, Burst: 10000 packets, enabled Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by individual policers: 0 FPC slot 2 information: Bandwidth: 100% (10000 pps), Burst: 100% (10000 packets), enabled Hostbound queue 3 Aggregate policer is never violated Received: 0 Arrival rate: 0 pps Dropped: 0 Max arrival rate: 0 pps Dropped by aggregate policer: 0 Dropped by flow suppression: 0
显示 DDoS 防护协议 IP 选项参数
user@host> show ddos-protection protocols ip-options parameters Packet types: 1, Modified: 0 * = User configured value Protocol Group: IP-Options Packet type: aggregate (Aggregate for all options traffic) Aggregate policer configuration: Bandwidth: 100 pps Burst: 100 packets Priority: Medium Recover time: 300 seconds Enabled: Yes Routing Engine information: Bandwidth: 100 pps, Burst: 100 packets, enabled FPC slot 0 information: Bandwidth: 100% (100 pps), Burst: 100% (100 packets), enabled Hostbound queue 255 FPC slot 1 information: Bandwidth: 100% (100 pps), Burst: 100% (100 packets), enabled Hostbound queue 255 FPC slot 7 information: Bandwidth: 100% (100 pps), Burst: 100% (100 packets), enabled Hostbound queue 255
发布信息
Junos OS 11.2 版中引入的命令。
Junos OS 17.3R1 版中添加了对增强订阅者管理的支持。
Junos OS 23.2R1 版中添加了对 ARP 广播和单播协议的支持。