protocols (DDoS)
Syntax
protocols protocol-group (aggregate | packet-type) { bandwidth packets-per-second; burst size; bypass-aggregate; disable-fpc; disable-logging; disable-routing-engine; flow-detection-mode (automatic | off | on); flow-detect-time seconds; flow-level-bandwidth { logical-interface flow-bandwidth; physical-interface flow-bandwidth; subscriber flow-bandwidth; } flow-level-control { logical-interface flow-control-mode; physical-interface flow-control-mode; subscriber flow-control-mode; } flow-level-detection { logical-interface flow-operation-mode; physical-interface flow-operation-mode; subscriber flow-operation-mode; } flow-recover-time seconds; flow-timeout-time seconds; fpc slot-number { bandwidth-scale percentage; burst-scale percentage; disable-fpc; } no-flow-logging priority level; recover-time seconds; timeout-active-flows; }
Hierarchy Level
[edit system ddos-protection]
Description
(MX Series routers with only MPCs, T4000 Core Routers with only FPC5s, or EX9200 switches) Configure control plane DDoS protection policers for all supported packet types within a protocol group or for a particular supported packet type within a protocol group.
Starting in Junos OS Release 22.2R1, we’ve enabled support for following DDoS protocol statements for MX10008 devices also. In earlier releases, the MX10008 devices did not support these DDoS protocol statements.
Filter-action
Virtual-chassis
Ttl
Redirect
Re-services
Re-services-v6
Rejectv6
L2pt
Syslog
Vxlan
For the available control plane DDoS protection policer configuration options on PTX Series routers and QFX Series switches, which are different from the options described here, see protocols (DDoS) (ACX Series, PTX Series, and QFX Series).
Although the term bandwidth usually refers to bits per
second (bps), this feature’s bandwidth
option represents
a packets per second (pps) value, and the burst
option
represents number of packets in a burst. These options are explained
separately.
Options
aggregate |
Configure the policer to monitor all control packets within the protocol group. You can configure an aggregate policer for any protocol group. |
packet-type |
(Optional) Name of the control packet type to be policed. You can configure a specific policer for only the following packet types and protocol groups:
|
protocol-group |
Name of the protocol group for which traffic is policed. You can configure a policer for any of the following protocol groups:
|
The remaining statements are explained separately. Search for a statement in CLI Explorer or click a linked statement in the Syntax section for details.
Required Privilege Level
admin—To view this statement in the configuration.
admin-control—To add this statement to the configuration.
Release Information
Statement introduced in Junos OS Release 11.2.
Support for Enhanced Subscriber Management added in Junos OS Release 17.3R1.