IP Reassembly 2048 1024 300
IP Local Icmp Frag 512 256 300
IP Local Frag 512 256 300
IP Application Classifier HTTP 128 64 300
Redirect
•
See show suspicious-control-flow-detection protocol.
Denial-of-Service Protection Groups
A DoS protection group provides a simple policy that can be applied to interfaces. This
policy can specify a complete set of parameters to tune the behavior of the DoS protection
groups. The system uses these parameters to determine the priority and rates for various
control protocols. The rate of traffic for a particular protocol is unlikely to be the same
on all ports in the system. A configuration can have several types of interfaces, such as
DHCP access clients, PPPoE access clients, and uplink interfaces. Each of these interfaces
requires a different DoS configuration. All interfaces are associated with a default DoS
protection group, which has standard system defaults. The maximum rates are per line
module, and the drop probability is 100 percent (all suspicious packets are dropped).
Group Parameters
DoS protection groups support the following set of parameters:
•
Protocol-to-priority mapping enables you to map a protocol to one of four priorities.
•
Protocol burst enables you to configure the burst level for the protocol. The burst is
configurable in packets, and defaults to a value in packets that is one half of the
maximum rate.
•
Protocol maximum rate limit (per line module) enables you to map a protocol to a
maximum rate limit. This rate limit applies to all packets for a particular protocol for
interfaces belonging to this particular DoS protection group on a line module. By having
a DoS protection group on a single line module, the total maximum rate for a protocol
can be up to the sum of the four rates configured, depending on the DoS group attached
to an interface. You can set a maximum rate of zero for protocols that are not used.
The actual rate never exceeds the maximum rate, but the actual rate allowed can be
less than the configured maximum rate because of the weighting of protocols within
a DoS protection group and the use of multiple DoS protection groups.
•
Protocol weight with respect to other protocols in the DoS protection group enables
you to balance the priority of the protocols. For each priority grouping, weight determines
the effective minimum rate that each protocol receives. Within each priority, the sum
of the minimum rates for all protocols using that priority is equal to or less than the
priority rate times the over-subscription value. Each priority has a separate rate for
each DoS protection group.
•
Protocol drop probability for suspicious packets enables you to map a protocol to a
specific drop probability. The drop probability is the percentage probability that a
suspicious packet is dropped.
•
Protocol skip priority rate limiter enables you to configure the system so that the
specified protocol is not subject to the priority rate limiter for the priority and DoS
Copyright © 2010, Juniper Networks, Inc.
446
JunosE 11.3.x System Basics Configuration Guide
Summary of Contents for JUNOSE 11.3
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 3 x System Basics Configuration Guide...
Page 24: ...Copyright 2010 Juniper Networks Inc xxiv JunosE 11 3 x System Basics Configuration Guide...
Page 32: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 3 x System Basics Configuration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 116 JunosE 11 3 x System Basics Configuration Guide...
Page 166: ...Copyright 2010 Juniper Networks Inc 136 JunosE 11 3 x System Basics Configuration Guide...
Page 432: ...Copyright 2010 Juniper Networks Inc 402 JunosE 11 3 x System Basics Configuration Guide...
Page 488: ...Copyright 2010 Juniper Networks Inc 458 JunosE 11 3 x System Basics Configuration Guide...
Page 524: ...Copyright 2010 Juniper Networks Inc 494 JunosE 11 3 x System Basics Configuration Guide...
Page 554: ...Copyright 2010 Juniper Networks Inc 524 JunosE 11 3 x System Basics Configuration Guide...
Page 566: ...Copyright 2010 Juniper Networks Inc 536 JunosE 11 3 x System Basics Configuration Guide...
Page 588: ...Copyright 2010 Juniper Networks Inc 558 JunosE 11 3 x System Basics Configuration Guide...
Page 613: ...PART 3 Index Index on page 585 583 Copyright 2010 Juniper Networks Inc...
Page 614: ...Copyright 2010 Juniper Networks Inc 584 JunosE 11 3 x System Basics Configuration Guide...
Page 632: ...Copyright 2010 Juniper Networks Inc 602 JunosE 11 3 x System Basics Configuration Guide...