Denial-Of-Service Protection Groups; Group Parameters - Juniper SYSTEM BASICS - CONFIGURATION GUIDE V 11.1.X Configuration Manual

System basics configuration guide software for e series broadband services routers
Table of Contents

Advertisement

Denial-of-Service Protection Groups

A DoS protection group provides a simple policy that can be applied to interfaces.
This policy can specify a complete set of parameters to tune the behavior of the DoS
protection groups. The system uses these parameters to determine the priority and
rates for various control protocols. The rate of traffic for a particular protocol is
unlikely to be the same on all ports in the system. A configuration can have several
types of interfaces, such as DHCP access clients, PPPoE access clients, and uplink
interfaces. Each of these interfaces requires a different DoS configuration. All
interfaces are associated with a default DoS protection group, which has standard
system defaults. The maximum rates are per line module, and the drop probability
is 100 percent (all suspicious packets are dropped).

Group Parameters

DoS protection groups support the following set of parameters:
IP Local PIM Assert
IP Local BFD
IP IKE
IP Reassembly
IP Local Icmp Frag
IP Local Frag
IP Application Classifier HTTP
Redirect
See show suspicious-control-flow-detection protocol.
Protocol-to-priority mapping enables you to map a protocol to one of four
priorities.
Protocol burst enables you to configure the burst level for the protocol. The burst
is configurable in packets, and defaults to a value in packets that is one half of
the maximum rate.
Protocol maximum rate limit (per line module) enables you to map a protocol
to a maximum rate limit. This rate limit applies to all packets for a particular
protocol for interfaces belonging to this particular DoS protection group on a line
module. By having a DoS protection group on a single line module, the total
maximum rate for a protocol can be up to the sum of the four rates configured,
depending on the DoS group attached to an interface. You can set a maximum
rate of zero for protocols that are not used. The actual rate never exceeds the
maximum rate, but the actual rate allowed can be less than the configured
maximum rate because of the weighting of protocols within a DoS protection
group and the use of multiple DoS protection groups.
Protocol weight with respect to other protocols in the DoS protection group
enables you to balance the priority of the protocols. For each priority grouping,
weight determines the effective minimum rate that each protocol receives. Within
each priority, the sum of the minimum rates for all protocols using that priority
is equal to or less than the priority rate times the over-subscription value. Each
priority has a separate rate for each DoS protection group.
Chapter 7: Passwords and Security
512
256
1024
512
512
256
2048
1024
512
256
512
256
128
64
Denial of Service (DoS) Protection
300
300
300
300
300
300
300
461

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.1

Table of Contents