[j-nsp] RE CPU DoS Filters

Marlon Duksa mduksa at gmail.com
Wed Aug 5 14:06:34 EDT 2009


Hi - is there any way to look at he default filters that are applied on the
RE? Or see what's being queued on the RE for processing, say RSVP packets,
or BGP packets, or IGMP packets, something along the 'netstat' command.
 We are dropping some control traffic into the RE. When we run the command
"run monitor traffic interface xxx' we see that we receive only 533 packets
by "filter". Which filter? We are sending 1000 packets but only receiving
533. We know that we do not have any filter on the interfaces. So this
filter, is it a control plane filter? How do we see it or change it?


1:03:09.553047  In IP 20.1.1.2 > 224.0.0.22: igmp v3 report, 1 group
record(s)
11:03:09.553048  In IP 20.1.1.2 > 224.0.0.22: igmp v3 report, 1 group
record(s)
11:03:09.553049  In IP 20.1.1.2 > 224.0.0.22: igmp v3 report, 1 group
record(s)
11:03:09.553051  In IP 20.1.1.2 > 224.0.0.22: igmp v3 report, 1 group
record(s)
^C^C
533 packets received by filter
0 packets dropped by kernel

Thanks,
Marlon


More information about the juniper-nsp mailing list