Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


flow-detection-mode (DDoS Flow Detection)


Hierarchy Level


(MX Series routers with only MPCs, T4000 Core Routers with only FPC5s, or EX9200 switches) Configure the mode of operation for flow detection for a protocol group or packet type. Use this statement to override global flow detection settings configured with the flow-detection-mode statement at the [edit system ddos-protection global] hierarchy level. The operation mode is effective only when flow detection is enabled.


The default mode for all protocol groups and packet types is automatic.



Detect flows only when the policer is being violated.


Disable flow detection.


Always monitor and detect flows, even when the policer is not being violated.

Required Privilege Level

admin—To view this statement in the configuration.

admin-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 12.3.

Support for Enhanced Subscriber Management added in Junos OS Release 17.3R1.