Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


flow-level-control (DDoS Global Flow Detection)


Hierarchy Level


(MX Series routers with only MPCs, T4000 Core Routers with only FPC5s, or EX9200 switches) Specify how traffic in the detected flow is handled globally for all protocol groups and packet types at all flow aggregation levels.

To override the global configuration for a protocol group or packet type, use the flow-level-control statement at the [edit system ddos-protection protocols protocol-group packet-type] hierarchy level to specify the flow control mode at one or more flow aggregation levels.



Mode for how traffic in the detected flow is controlled globally.

  • drop—Drop all traffic in flow.

  • keep—Keep all traffic in flow.

  • police—Police the traffic to within its allowed bandwidth.

  • Default: drop

Required Privilege Level

admin—To view this statement in the configuration.

admin-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 17.1.