14.12.2012 Views

Junos OS Interfaces Command Reference - Juniper Networks

Junos OS Interfaces Command Reference - Juniper Networks

Junos OS Interfaces Command Reference - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CHAPTER 25<br />

Discard Interface Operational Mode<br />

<strong>Command</strong>s<br />

Table 161 on page 927 summarizes the command-line interface (CLI) command that you<br />

can use to monitor and troubleshoot the discard (dsc) interface.<br />

Table 161: Discard Interface Operational Mode <strong>Command</strong>s<br />

Task<br />

Monitor the discard interface.<br />

<strong>Command</strong><br />

show interfaces (Discard)<br />

The discard interface is not a physical interface, but a virtual interface that discards<br />

packets. You can configure one discard interface. The discard interface allows you to<br />

identify the ingress point of a denial-of-service (DoS) attack. When your network is under<br />

attack, the target host IP address is identified, and the local policy forwards attacking<br />

packets to the discard interface. Traffic routed out of the discard interface is silently<br />

discarded.<br />

Copyright © 2012, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

If an output filter is attached to the interface, the action specified by the filter causes the<br />

packets to be logged or counted before the traffic is discarded. For a complete discussion<br />

about using the discard interface to protect your network against DoS attacks, see the<br />

<strong>Junos</strong> Policy Framework Configuration Guide.<br />

Statistics and media displayed by the show interfaces command are not relevant for the<br />

discard interface and always show values of 0.<br />

927

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!