Description

DDOS Aggregate Packet Limit for the L3MTU-fail


root@router> show ddos-protection protocols l3mtu-fail

Packet types: 1, Modified: 1, Received traffic: 1, Currently violated: 0

Currently tracked flows: 0, Total detected flows: 0

* = User configured value


Protocol Group: L3MTU-fail


Packet type: aggregate (Aggregate for L3 MTU Check fail)

Aggregate policer configuration:

Bandwidth: 300 pps* <<<<<< This has been changed to 50 pps from 22.3 onwards

Burst: 400 packets*

Recover time: 300 seconds

Enabled: Yes

Flow detection configuration:

Flow detection system is off

Detection mode: Automatic Detect time: 0 seconds

Log flows: Yes Recover time: 0 seconds

Timeout flows: No Timeout time: 0 seconds

Flow aggregation level configuration:

Aggregation level Detection mode Control mode Flow rate

Subscriber Automatic Drop 0 pps

Logical interface Automatic Drop 0 pps

Physical interface Automatic Drop 50 pps

System-wide information:

Aggregate bandwidth is no longer being violated

Received: 493951 Arrival rate: 167 pps

Dropped: 0 Max arrival rate: 258 pps

Routing Engine information:

Bandwidth: 300 pps, Burst: 400 packets, enabled

Aggregate policer is never violated

Received: 0 Arrival rate: 0 pps

Dropped: 0 Max arrival rate: 0 pps

Dropped by individual policers: 0

FPC slot 0 information:

Bandwidth: 100% (300 pps), Burst: 100% (400 packets), enabled

Hostbound queue 255

Aggregate policer is no longer being violated

Received: 493951 Arrival rate: 167 pps

Dropped: 0 Max arrival rate: 258 pps

Dropped by flow suppression: 0



Symptoms

DDOS messages

Solution

The L3MTU-Fail Aggregate DDOS Packet Limit has been modified to 50 pps from 22.3 onwards. Prior to 22.3 the limit was 300 pps.

The new value will be 50 pps

root@router> show ddos-protection protocols l3mtu-fail 

Packet types: 1, Modified: 0, Received traffic: 0, Currently violated: 0

Currently tracked flows: 0, Total detected flows: 0

* = User configured value

Protocol Group: L3MTU-fail

Packet type: aggregate (Aggregate for L3 MTU Check fail)

  Aggregate policer configuration:

   Bandwidth:    50 pps <<<<<< The new value

   Burst:      10 packets

   Priority:     Low

   Recover time:   300 seconds

   Enabled:     Yes

  Flow detection configuration:

   Flow detection system is off

   Detection mode: Automatic Detect time: 0 seconds

   Log flows:   Yes    Recover time: 0 seconds

   Timeout flows: No     Timeout time: 0 seconds

   Flow aggregation level configuration:

    Aggregation level  Detection mode Control mode Flow rate

    Subscriber     Automatic    Drop     0 pps

    Logical interface  Automatic    Drop     0 pps

    Physical interface Automatic    Drop     50 pps

  System-wide information:

   Aggregate bandwidth is never violated

   Received: 0          Arrival rate:   0 pps

   Dropped:  0          Max arrival rate: 0 pps

  Routing Engine information:

   Bandwidth: 50 pps, Burst: 10 packets, enabled

   Aggregate policer is never violated

   Received: 0          Arrival rate:   0 pps

   Dropped:  0          Max arrival rate: 0 pps

    Dropped by individual policers: 0

  FPC slot 0 information:

   Bandwidth: 100% (50 pps), Burst: 100% (10 packets), enabled

   Hostbound queue 12

   Aggregate policer is never violated

   Received: 0          Arrival rate:   0 pps

   Dropped:  0          Max arrival rate: 0 pps

    Dropped by individual policers: 0

    Dropped by flow suppression:  0





Modification History

2024-11-15 : Article Created