Re: [j-nsp] MX80 pfe hardware input drops

2014-01-31 Thread Alexander Kasatkin
Thanks a lot, Saku. 2014-01-31 Saku Ytti : > On (2014-01-31 11:02 +0200), Alexander Kasatkin wrote: > >> But I don't have any reject action in firewall rules. Please point me >> to right direction. > > This would be any packet which has DADDR pointing to FIB entry with type > 'reject'. > In more p

Re: [j-nsp] MX80 pfe hardware input drops

2014-01-31 Thread Saku Ytti
On (2014-01-31 11:02 +0200), Alexander Kasatkin wrote: > But I don't have any reject action in firewall rules. Please point me > to right direction. This would be any packet which has DADDR pointing to FIB entry with type 'reject'. In more practical terms, destination to which you don't have rout

[j-nsp] MX80 pfe hardware input drops

2014-01-31 Thread Alexander Kasatkin
Hello community, I've strange behavior of my MX80 (junos version 11.4R8.4) under ddos attacks. Router drops all bgp sessions (hold timer expiry) with a 3-5gbps ddos. Can someone explain me what a hardware input drops is: snoop@mx80> show pfe statistics traffic Packet Forwarding Engine traffic s