Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

by-source (IDS Screen Next Gen Services)

date_range 19-Nov-23

Syntax

content_copy zoom_out_map
by-source {
    by-protocol {
        icmp {
            maximum-sessions number;
            packet-rate number;
            session-rate number;
        }
        tcp {
            maximum-sessions number;
            packet-rate number;
            session-rate number;
        }
        udp {
            maximum-sessions number;
            packet-rate number;
            session-rate number;
        }
    }
    maximum-sessions number;
    packet-rate number;
    session-rate number;
    ;
}

Hierarchy Level

content_copy zoom_out_map
[edit services screen ids-option screen-name limit-session]

Description

Configure session limits for individual source addresses or for individual source subnets. This protects against network probing attacks and network flooding attacks. You can specify limits for specific protocols (ICMP, TCP, and UDP), or specify limits independent of a protocol. When a session limit is exceeded for a source, packets from the source are dropped until the session limit is no longer exceeded.

To specify limits for source subnets rather than individual addresses, include the aggregations statement at the [edit services screen ids-option screen-name] hierarchy level.

Options

maximum-sessions number

Specify the maximum number of concurrent sessions allowed for an individual source address or subnet.

packet-rate number

Specify the maximum number of packets per second allowed for an individual source address or subnet.

session-rate number

Specify the maximum number of connections per second allowed for an individual source address or subnet.

The remaining statements are explained separately. See CLI Explorer.

Required Privilege Level

interface—To view this statement in the configuration.

interface-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 19.3R2.

footer-navigation