Attaching Groups
Protocol Mapping
Copyright © 2010, Juniper Networks, Inc.
protection group selected. The default is off—the protocol is subject to priority rate
limiting.
Priority rate sets the rate of the priority in packets per second for the line module. If
this rate is exceeded, it triggers DoS suspicious control flow detection.
Priority burst enables you to set the number of packets allowed to exceed the maximum
rate before packets are dropped and DoS suspicious control flow detection is triggered.
Priority oversubscription enables you to set an oversubscription factor for the priority
rate limiter. In addition to the priority rate, it calculates the minimum rate limits for
protocols with a priority grouping and allows for oversubscription of the priority rate.
The value indicates a percentage that the priority rate limiter is allowed to be
oversubscribed, in the range 100–1000.
By default, each interface belongs to the default DoS protection group. The name is the
only non-configurable aspect of the default DoS protection group.
The DoS protection group is a configurable parameter for all Layer 2 and IP interfaces.
Similar to other configurable interface parameters, the DoS protection group can be set
using profiles.
Because all newly created interfaces default to using the default DoS protection group,
they do not inherit any DoS protection group association from a higher or lower interface
binding.
The DoS group applies to all types of control flows for the specific interface. For example,
an IP interface supports a variety of control protocols, each of which can be separately
mapped to a priority and drop probability, but to a single DoS protection group.
Table 49 on page 447 and Table 50 on page 449 list the protocols mapped within DoS
protection groups.
Table 49: Layer 2-Related Protocols
CLI Name
Description of Flow
atmControl
ATM ILMI packets
atmOAM
ATM OAM packets
atmDynamicIf
ATM dynamic interface column creation
atmInverseArp
ATM inverse ARP packets
dhcpExternal
DHCP external packets
Chapter 7: Passwords and Security
447
Need help?
Do you have a question about the JUNOSE SOFTWARE FOR E SERIES 11.3.X - SYSTEM BASICS CONFIGURATION GUIDE 2010-10-04 and is the answer not in the manual?