Multicast traffic is being affected (clock sync issues). Based on these entries, is there a way to see if the ddos protection is affecting the clock sync issues?
Jan 8 22:09:31 r1 ddosd[7587]: DDOS_PROTOCOL_VIOLATION_CLEAR: INFO: Host-bound traffic for protocol/exception IPMCAST-miss:aggregate has returned to normal. Its allowed bandwidth was exceeded at fpc 0 for 3 times, from 2025-12-13 12:59:29 EET to 2026-01-08 22:04:27 EET
Jan 8 22:10:19 r1 ddosd[7587]: DDOS_PROTOCOL_VIOLATION_SET: Warning: Host-bound traffic for protocol/exception IPMCAST-miss:aggregate exceeded its allowed bandwidth at fpc 0 for 4 times, started at 2026-01-08 22:10:19 EET
As per logs, IP Multicast is certainly getting violated & will generate the aggregate violation logs you are seeing.
And could be the reason as clock sync uses Mcast.
Packet type: aggregate (Aggregate for IP Multicast Miss to cpu)
Aggregate policer configuration:
Bandwidth: 1024 pps
Burst: 512 packets
Priority: High
Recover time: 300 seconds
Enabled: Yes
System-wide information:
Aggregate bandwidth is being violated!
No. of FPCs currently receiving excess traffic: 1
No. of FPCs that have received excess traffic: 1
Violation first detected at: 2026-01-08 22:10:19 EET
Violation last seen at: 2026-01-22 13:13:32 EET
Duration of violation: 1w6d 15:03 Number of violations: 4
Received: 45290605935 Arrival rate: 14473 pps
Dropped: 41268798679 Max arrival rate: 48866 pps
Routing Engine information:
Bandwidth: 1024 pps, Burst: 512 packets, enabled
Aggregate policer is never violated
Received: 0 Arrival rate: 0 pps
Dropped: 0 Max arrival rate: 0 pps
Dropped by individual policers: 0
FPC slot 0 information:
Bandwidth: 100% (1024 pps), Burst: 100% (512 packets), enabled
Aggregate policer is currently being violated!
Dropped by aggregate policer: 41268798679
Dropped by flow suppression: 0
Cusotmer changed default value to 15k, based on the Arrival rate.
But the suggestion from our side was to identify the source & stop this from there, as 15k BW is certainly on higher side.
set system ddos-protection protocols ipmcast-miss aggregate bandwidth <>
set system ddos-protection protocols ipmcast-miss aggregate burst <>
Another option is to add firewall filter to block the group causing the issue.
Sample (address is the MCast group):
set firewall family inet filter DROP-MCAST-GROUP term BLOCK-GP1 from destination-address a.b.c.d/32
set firewall family inet filter DROP-MCAST-GROUP term BLOCK-GP1 from protocol igmp/pim
set firewall family inet filter DROP-MCAST-GROUP term BLOCK-GP1 then discard
set firewall family inet filter DROP-MCAST-GROUP term ALLOW-REST then accept