Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

show ddos-protection protocols culprit-flows

Syntax

Description

Display culprit flow information for protocol groups or individual packet types.

Options

none

Display information for all protocol groups and packet types.

brief | detail

(Optional) Display the specified level of output.

fpc-slot

(Optional) Display information for the specified Flexible PIC Concentrator (FPC) slot.

  • Default: system-wide, that is; include all the FPC slots.

  • Range: 0 through 2

summary

(Optional) Display flow information summary.

aggregate

(Optional) Display DDoS protection information for the aggregate policer. The aggregate option is available for all protocol groups.

packet-type

(Optional) Display information for the specified packet type in the protocol group. The available packet types vary by protocol group.

See show ddos-protection protocols for a list of available packet types.

protocol-group

(Optional) Display information for a particular protocol group.

See show ddos-protection protocols for a list of available groups.

Required Privilege Level

view

Output Fields

Table 1 lists the output fields for the show ddos-protection protocols culprit-flows command. Output fields are listed in the approximate order in which they appear.

Table 1: show ddos-protection protocols culprit-flows Output Fields

Field Name

Field Description

Level of Output

Currently tracked flows

Number of active flows that are being tracked as culprit flows by flow detection.

All levels

Total detected flows

Total number of culprit flows that have been detected, including those that have recovered or timed out.

All levels

Protocol Group

Name of protocol group.

detail

Packet type

Name of packet type in protocol group.

detail

Arriving Interface

Logical interface on which the traffic flow arrived.

detail

Aggr Flow Id level

Shows the flow_id, such as flow_id 0001000000000022

detail

Source Address MAC or IP

Source address of the traffic flow, either a MAC address or an IP address.

detail

Destination Address MAC or IP

Destination address of the traffic flow, either a MAC address or an IP address.

detail

Source Port

Source port number.

detail

Destination Port

Destination port number.

detail

pps

Rate of the traffic flow in packets per second.

brief

Rate

Rate of the traffic flow in packets per second.

detail

pkts

Number of packets received in the traffic flow.

brief

received packets

Number of packets received in the traffic flow.

detail

Additional information

Flow ID numbers automatically assigned to flow, with embedded slot ID. The flow ID is prefixed by sub, ifl, or ifd, which indicate the subscriber, logical interface, and physical interface flow aggregation levels.

Timestamp that identifies when the flow arrived on the interface.

detail

Sample Output

show ddos-protection protocols culprit-flows brief

show ddos-protection protocols culprit-flows for all protocols

show ddos-protection protocols culprit-flows detail (Specific Protocol Group)

show expanded format for dhcpv4 discover packet type

show dhcpv4 flow detection information

show dhcpv4 flow detection information in brief format

show global statistics

show ddos-protection protocols culprit-flows fpc-slot

Release Information

Command introduced in Junos OS Release 12.3.

Support for Enhanced Subscriber Management added in Junos OS Release 17.3R1.