Description

Multicast traffic is being affected (clock sync issues). Based on these entries, is there a way to see if the ddos protection is affecting the clock sync issues?

Symptoms

Jan 8 22:09:31 r1 ddosd[7587]: DDOS_PROTOCOL_VIOLATION_CLEAR: INFO: Host-bound traffic for protocol/exception IPMCAST-miss:aggregate has returned to normal. Its allowed bandwidth was exceeded at fpc 0 for 3 times, from 2025-12-13 12:59:29 EET to 2026-01-08 22:04:27 EET

Jan 8 22:10:19 r1 ddosd[7587]: DDOS_PROTOCOL_VIOLATION_SET: Warning: Host-bound traffic for protocol/exception IPMCAST-miss:aggregate exceeded its allowed bandwidth at fpc 0 for 4 times, started at 2026-01-08 22:10:19 EET

 

Solution

As per logs, IP Multicast is certainly getting violated & will generate the aggregate violation logs you are seeing.

And could be the reason as clock sync uses Mcast.

 

 Packet type: aggregate (Aggregate for IP Multicast Miss to cpu)

   Aggregate policer configuration:

     Bandwidth:       1024 pps

     Burst:           512 packets

     Priority:        High

     Recover time:    300 seconds

     Enabled:         Yes

   System-wide information:

     Aggregate bandwidth is being violated!

       No. of FPCs currently receiving excess traffic: 1

       No. of FPCs that have received excess traffic: 1

       Violation first detected at: 2026-01-08 22:10:19 EET

       Violation last seen at:     2026-01-22 13:13:32 EET

       Duration of violation: 1w6d 15:03 Number of violations: 4

     Received: 45290605935        Arrival rate:    14473 pps

     Dropped:  41268798679        Max arrival rate: 48866 pps

   Routing Engine information:

     Bandwidth: 1024 pps, Burst: 512 packets, enabled

     Aggregate policer is never violated

     Received: 0                  Arrival rate:    0 pps

     Dropped:  0                  Max arrival rate: 0 pps

       Dropped by individual policers: 0

   FPC slot 0 information:

     Bandwidth: 100% (1024 pps), Burst: 100% (512 packets), enabled

     Aggregate policer is currently being violated!

       Violation first detected at: 2026-01-08 22:10:19 EET

       Violation last seen at:     2026-01-22 13:13:32 EET

       Duration of violation: 1w6d 15:03 Number of violations: 4

     Received: 45290605935        Arrival rate:    14473 pps

     Dropped:  41268798679        Max arrival rate: 48866 pps

       Dropped by individual policers: 0

       Dropped by aggregate policer:  41268798679

       Dropped by flow suppression:   0

 

Cusotmer changed default value to 15k, based on the Arrival rate.

But the suggestion from our side was to identify the source & stop this from there, as 15k BW is certainly on higher side.

 

set system ddos-protection protocols ipmcast-miss aggregate bandwidth <>

set system ddos-protection protocols ipmcast-miss aggregate burst <>

 

Another option is to add firewall filter to block the group causing the issue.

 

Sample (address is the MCast group):

set firewall family inet filter DROP-MCAST-GROUP term BLOCK-GP1 from destination-address a.b.c.d/32

set firewall family inet filter DROP-MCAST-GROUP term BLOCK-GP1 from protocol igmp/pim

set firewall family inet filter DROP-MCAST-GROUP term BLOCK-GP1 then discard

set firewall family inet filter DROP-MCAST-GROUP term ALLOW-REST then accept

Modification History

2026-01-30 : Article Created