Re: [j-nsp] ddos protocol protection - IPv4-unclassified

2017-04-09 Thread Mark Tees
From memory when I last tested this the default settings were pretty bad when under DOS conditions (IGP,BGP going down due to packets being dropped). Ytti will probably pop up and comment on this but we have flow-detection configured under global for ddos-protection which create flows then actions

Re: [j-nsp] ddos protocol protection - IPv4-unclassified

2017-04-09 Thread Cahit Eyügünlü
We are facing the exact Same thing with mx80 iPhone'umdan gönderildi James Jun şunları yazdı (10 Nis 2017 09:14): > Hello Folks, > > We had a strange DoS attack against a customer attached to an MX104 router > that caused the device to > completely stop forwarding all legitimate traffic (routi

[j-nsp] ddos protocol protection - IPv4-unclassified

2017-04-09 Thread James Jun
Hello Folks, We had a strange DoS attack against a customer attached to an MX104 router that caused the device to completely stop forwarding all legitimate traffic (routing protocols both igp and bgp timed out across all adjacencies and sessions). The attack traffic was roughly 5.9 Gbps and it

[j-nsp] EX3200/4200 ipv6 match conditions in family ethernet-switching

2017-04-09 Thread Jason Healy
I've been burned plenty of times by the (lack of) IPv6 feature parity, so I'm hoping the list's collective wisdom can save me from a lot of extra testing and phone calls with JTAC... TL;DR: are ANY layer 3 match conditions supported for IPv6 in family ethernet-switching on the EX3200/4200? The

Re: [j-nsp] flowspec in logical-systems

2017-04-09 Thread Thomas Bellman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 2017-04-07 20:43, Aaron Gould wrote: > Do you all use logical-systems in your operational network? How pleased are > you with them? I have an MX104 with about 8 lsys's and I am using it for a > study lab and love it. Our ISP uses logical systems