This feature supports DDoS rate limiting for telemetry traffic to enhance host path protection and provide improved control over telemetry traffic volume. Telemetry traffic, which uses TCP to stream network data for real-time analysis, was previously classified under the default unclassified DDoS protocol. Telemetry traffic is now mapped to a dedicated DDoS protocol, enabling targeted rate limiting, bandwidth control, and traffic monitoring.
The telemetry server IP address (optional, depending on configuration) and TCP port (mandatory) are used as match terms by the DDoS filter for telemetry traffic. DDoS rate limiting is implemented on a packets-per-second basis and is independent of packet size. The telemetry DDoS policer applies to ingress traffic and rate-limits TCP acknowledgment (ACK) packets from the collector to the device.
This feature applies only to TCP-based telemetry traffic and does not support UDP telemetry traffic. You can subscribe to the /junos/system/linecard/ddos/ resource path to stream DDoS statistics.
| Product / Application | Software | Introduced Release |
|---|---|---|
| PTX10003 | Junos OS Evolved | 26.2R1 |