ddos dst zone ip-proto proto-name¶
DDOS IP protocol configuration
proto-name Specification¶
Type
Collection
Object Key(s)
protocol
Collection Name
Collection URI
/axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name
Element Name
proto-name
Element URI
/axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}
Element Attributes
proto-name_attributes
Statistics Data URI
/axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/stats
Operational Data URI
/axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/oper
Schema
Operations Allowed:
Operation | Method | URI | Payload | |
---|---|---|---|---|
Create Object | POST | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name | ||
Create List | POST | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name | ||
Get Object | GET | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol} | ||
Get List | GET | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name | ||
Modify Object | POST | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol} | ||
Replace Object | PUT | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol} | ||
Replace List | PUT | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name | ||
Delete Object | DELETE | /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol} |
proto-name-list¶
proto-name-list is JSON List of proto-name attributes
proto-name-list : [
]
proto-name attributes¶
age
Description Idle age for ip entry
Type: number
Range: 2-1023
Default: 5
apply-policy-on-overflow
Description Enable this flag to apply overflow policy when dynamic entry count overflows
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
deny
Description Blacklist and Drop all incoming packets for ip-proto icmp-v4
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
drop-frag-pkt
Description Drop fragmented packets
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
dynamic-entry-overflow-policy-list
Type: List
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/dynamic-entry-overflow-policy/{dummy-name}
enable-class-list-overflow
Description Apply class-list overflow policy upon exceeding dynamic entry count specified for zone-port or class-list
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
enable-top-k
Description Enable ddos top-k source IP detection
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
enable-top-k-destination
Description Enable ddos top-k destination IP detection
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
glid-cfg
Description: glid-cfg is a JSON Block. Please see below for glid-cfg
Type: Object
key-cfg
Type: List
level-list
Type: List
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/level/{level-num}
manual-mode-enable
Description Toggle manual mode to use fix templates
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
manual-mode-list
Type: List
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/manual-mode/{config}
max-dynamic-entry-count
Description Maximum count for dynamic source zone service entry
Type: number
Range: 0-2147483647
port-ind
Description: port-ind is a JSON Block. Please see below for port-ind
Type: Object
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/port-ind
protocol
Description ‘icmp-v4’: ip-proto icmp-v4; ‘icmp-v6’: ip-proto icmp-v6; ‘other’: ip-proto other; ‘gre’: ip-proto gre; ‘ipv4-encap’: ip-proto IPv4 Encapsulation; ‘ipv6-encap’: ip-proto IPv6 Encapsulation;
Type: string
Supported Values: icmp-v4, icmp-v6, other, gre, ipv4-encap, ipv6-encap
set-counter-base-val
Description Set T2 counter value of current context to specified value
Type: number
Range: 1-4294967295
src-based-policy-list
Type: List
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/src-based-policy/{src-based-policy-name}
topk-destinations
Description: topk-destinations is a JSON Block. Please see below for topk-destinations
Type: Object
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/topk-destinations
topk-dst-num-records
Description Maximum number of records to show in topk
Type: number
Range: 1-100
Default: 20
topk-num-records
Description Maximum number of records to show in topk
Type: number
Range: 1-100
Default: 20
topk-sources
Description: topk-sources is a JSON Block. Please see below for topk-sources
Type: Object
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/topk-sources
tunnel-decap
Description Enable tunnel decapsulation
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
tunnel-rate-limit
Description Enable DDOS-protection on tunnel traffic
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
unlimited-dynamic-entry-count
Description No limit for maximum dynamic src entry count
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
dynamic-entry-overflow-policy-list¶
Specification
Type
list
Block object keys
action
Description ‘bypass’: Always permit for the Source to bypass all feature & limit checks; ‘deny’: Blacklist incoming packets for service;
Type: string
Supported Values: bypass, deny
dummy-name
Description ‘configuration’: Configure overflow policy;
Type: string
Supported Values: configuration
glid
Description Global limit ID
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/glid
user-tag
Description Customized tag
Type: string
Format: string-rlx
Maximum Length: 127 characters
Maximum Length: 1 characters
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
zone-template
Description: zone-template is a JSON Block. Please see below for dynamic-entry-overflow-policy-list_zone-template
Type: Object
dynamic-entry-overflow-policy-list_zone-template¶
Specification
Type
object
encap
Description DDOS encap template (IPv6-over-IPv4 / IPv4-over-IPv6 are not supported.)
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v4
Description DDOS icmp-v4 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v6
Description DDOS icmp-v6 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
ip-proto
Description DDOS ip-proto template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
key-cfg¶
Specification
Type
list
Block object keys
key
Description Only decapsulate GRE packet with this key (Hexadecimal 0x0-0xFFFFFFFF,decimal 0-4294967295)
Type: string
Maximum Length: 10 characters
Maximum Length: 1 characters
glid-cfg¶
Specification
Type
object
action-list
Description Configure action-list to take
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/ddos/action-list
glid
Description Global limit ID for the whole zone
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/glid
glid-action
Description ‘drop’: Drop packets for glid exceed (Default); ‘ignore’: Do nothing for glid exceed;
Type: string
Supported Values: drop, ignore
per-addr-glid
Description Global limit ID per address
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/glid
level-list¶
Specification
Type
list
Block object keys
glid-action
Description ‘drop’: Drop packets for glid exceed (Default); ‘blacklist-src’: Blacklist-src for glid exceed; ‘ignore’: Do nothing for glid exceed;
Type: string
Supported Values: drop, blacklist-src, ignore
indicator-list
Type: List
Refernce Object: /axapi/v3/ddos/dst/zone/{zone-name}/ip-proto/proto-name/{protocol}/level/{level-num}/indicator/{type}
level-num
Description ‘0’: Default policy level; ‘1’: Policy level 1; ‘2’: Policy level 2; ‘3’: Policy level 3; ‘4’: Policy level 4;
Type: string
Supported Values: 0, 1, 2, 3, 4
src-default-glid
Description Global limit ID
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/glid
src-escalation-score
Description Source activation score of this level
Type: number
Range: 1-1000000
src-violation-actions
Description Violation actions apply due to source escalate from this level
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/ddos/violation-actions
user-tag
Description Customized tag
Type: string
Format: string-rlx
Maximum Length: 127 characters
Maximum Length: 1 characters
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
zone-escalation-score
Description Zone activation score of this level
Type: number
Range: 1-1000000
zone-template
Description: zone-template is a JSON Block. Please see below for level-list_zone-template
Type: Object
zone-violation-actions
Description Violation actions apply due to zone escalate from this level
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/ddos/violation-actions
level-list_zone-template¶
Specification
Type
object
encap
Description DDOS encap template (IPv6-over-IPv4 / IPv4-over-IPv6 are not supported.)
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v4
Description DDOS icmp-v4 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v6
Description DDOS icmp-v6 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
ip-proto
Description DDOS ip-proto template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
level-list_indicator-list¶
Specification
Type
list
Block object keys
data-packet-size
Description Expected minimal data size
Type: number
Range: 1-1500
score
Description Score corresponding to the indicator
Type: number
Range: 1-1000000
src-threshold-num
Description Indicator per-src threshold
Type: number
Range: 1-2147483647
src-threshold-str
Description Indicator per-src threshold (Non-zero floating point)
Type: string
Maximum Length: 128 characters
Maximum Length: 1 characters
src-violation-actions
Description Violation actions to use when this src indicator threshold reaches
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/ddos/violation-actions
type
Description ‘pkt-rate’: rate of incoming packets; ‘pkt-drop-rate’: rate of packets got dropped; ‘bit-rate’: rate of incoming bits; ‘pkt-drop-ratio’: ratio of incoming packet rate divided by the rate of dropping packets; ‘bytes-to-bytes-from-ratio’: ratio of incoming packet rate divided by the rate of outgoing packets; ‘frag-rate’: rate of incoming fragmented packets; ‘cpu-utilization’: average data CPU utilization; ‘interface-utilization’: outside interface utilization;
Type: string
Supported Values: pkt-rate, pkt-drop-rate, bit-rate, pkt-drop-ratio, bytes-to-bytes-from-ratio, frag-rate, cpu-utilization, interface-utilization
user-tag
Description Customized tag
Type: string
Format: string-rlx
Maximum Length: 127 characters
Maximum Length: 1 characters
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
zone-threshold-num
Description Threshold for the entire zone
Type: number
Range: 1-2147483647
zone-threshold-str
Description Threshold for the entire zone (Non-zero floating point)
Type: string
Maximum Length: 128 characters
Maximum Length: 1 characters
zone-violation-actions
Description Violation actions to use when this zone indicator threshold reaches
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/ddos/violation-actions
manual-mode-list¶
Specification
Type
list
Block object keys
config
Description ‘configuration’: Manual-mode configuration;
Type: string
Supported Values: configuration
glid-action
Description ‘drop’: Drop packets for glid exceed (Default); ‘blacklist-src’: Blacklist-src for glid exceed; ‘ignore’: Do nothing for glid exceed;
Type: string
Supported Values: drop, blacklist-src, ignore
src-default-glid
Description Global limit ID
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/glid
user-tag
Description Customized tag
Type: string
Format: string-rlx
Maximum Length: 127 characters
Maximum Length: 1 characters
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
zone-template
Description: zone-template is a JSON Block. Please see below for manual-mode-list_zone-template
Type: Object
manual-mode-list_zone-template¶
Specification
Type
object
encap
Description DDOS encap template (IPv6-over-IPv4 / IPv4-over-IPv6 are not supported.)
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v4
Description DDOS icmp-v4 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v6
Description DDOS icmp-v6 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
ip-proto
Description DDOS ip-proto template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
src-based-policy-list¶
Specification
Type
list
Block object keys
policy-class-list-list
src-based-policy-name
Description Specify name of the policy
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
user-tag
Description Customized tag
Type: string
Format: string-rlx
Maximum Length: 127 characters
Maximum Length: 1 characters
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
src-based-policy-list_policy-class-list-list¶
Specification
Type
list
Block object keys
action
Description ‘bypass’: Always permit for the Source to bypass all feature & limit checks; ‘deny’: Blacklist incoming packets for service;
Type: string
Supported Values: bypass, deny
class-list-name
Description Class-list name
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
class-list-overflow-policy-list
glid
Description Global limit ID
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/glid
glid-action
Description ‘drop’: Drop packets for glid exceed (Default); ‘blacklist-src’: Blacklist-src for glid exceed; ‘ignore’: Do nothing for glid exceed;
Type: string
Supported Values: drop, blacklist-src, ignore
log-enable
Description Enable logging
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
log-periodic
Description Enable log periodic
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
max-dynamic-entry-count
Description Maximum count for dynamic source zone service entry allowed for this class-list
Type: number
Range: 0-2147483647
user-tag
Description Customized tag
Type: string
Format: string-rlx
Maximum Length: 127 characters
Maximum Length: 1 characters
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
zone-template
Description: zone-template is a JSON Block. Please see below for src-based-policy-list_policy-class-list-list_zone-template
Type: Object
src-based-policy-list_policy-class-list-list_zone-template¶
Specification
Type
object
encap
Description DDOS encap template (IPv6-over-IPv4 / IPv4-over-IPv6 are not supported.)
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v4
Description DDOS icmp-v4 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v6
Description DDOS icmp-v6 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
ip-proto
Description DDOS ip-proto template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
logging
Description DDOS logging template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
src-based-policy-list_policy-class-list-list_class-list-overflow-policy-list¶
Specification
Type
list
Block object keys
action
Description ‘bypass’: Always permit for the Source to bypass all feature & limit checks; ‘deny’: Blacklist incoming packets for service;
Type: string
Supported Values: bypass, deny
dummy-name
Description ‘configuration’: Configure overflow policy for class-list;
Type: string
Supported Values: configuration
glid
Description Global limit ID
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
Refernce Object: /axapi/v3/glid
log-enable
Description Enable logging
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
log-periodic
Description Enable log periodic
Type: boolean
Supported Values: true, false, 1, 0
Default: 0
user-tag
Description Customized tag
Type: string
Format: string-rlx
Maximum Length: 127 characters
Maximum Length: 1 characters
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
zone-template
Description: zone-template is a JSON Block. Please see below for src-based-policy-list_policy-class-list-list_class-list-overflow-policy-list_zone-template
Type: Object
src-based-policy-list_policy-class-list-list_class-list-overflow-policy-list_zone-template¶
Specification
Type
object
encap
Description DDOS encap template (IPv6-over-IPv4 / IPv4-over-IPv6 are not supported.)
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v4
Description DDOS icmp-v4 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
icmp-v6
Description DDOS icmp-v6 template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
ip-proto
Description DDOS ip-proto template
Type: string
Format: string-rlx
Maximum Length: 63 characters
Maximum Length: 1 characters
port-ind¶
Specification
Type
object
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
topk-sources¶
Specification
Type
object
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
topk-destinations¶
Specification
Type
object
uuid
Description uuid of the object
Type: string
Maximum Length: 64 characters
Maximum Length: 1 characters
stats ipproto-icmp¶
Counter |
Size |
Description |
|
---|---|---|---|
secondary_port_kbit_rate_exceed_pkt |
8 |
Per Addr-Port KiBit Rate Exceeded Count |
|
port_src_bl |
8 |
Src Blacklisted |
|
src_zone_service_entry_aged |
8 |
SrcZoneService Entry Aged |
|
outbound_port_drop |
8 |
Outbound Packets Dropped |
|
secondary_port_pkt_rate_exceed |
8 |
Per Addr-Port Packet Rate Exceeded |
|
rate_type2_exceed_drop |
8 |
ICMP Type Dst Rate 3 Dropped |
|
src_rate_type0_exceed_drop |
8 |
ICMP Type Src Rate 1 Dropped |
|
port_bytes_drop |
8 |
Inbound Bytes Dropped |
|
rate_type2_exceed_bl |
8 |
ICMP Type Dst Rate 3 Blacklisted |
|
outbound_port_bytes_sent |
8 |
Outbound Bytes Forwarded |
|
dst_hw_drop |
8 |
Dst Hardware Packets Dropped |
|
src_hw_drop_removed |
8 |
Src Hardware Drop Rules Removed |
|
port_pkt_rate_exceed |
8 |
Packet Rate Exceeded |
|
src_rate_type0_exceed |
8 |
ICMP Type Src Rate 1 Exceeded |
|
src_rate_type2_exceed |
8 |
ICMP Type Src Rate 3 Exceeded |
|
port_kbit_rate_exceed_pkt |
8 |
KiBit Rate Exceeded Count |
|
no_policy_class_list_match |
8 |
No Policy Class-list Match |
|
icmpv6_rfc_undef_drop |
8 |
ICMPv6 RFC Undef Type Dropped |
|
rate_type1_exceed |
8 |
ICMP Type Dst Rate 2 Exceeded |
|
dst_hw_drop_inserted |
8 |
Dst Hardware Drop Rules Inserted |
|
src_zone_service_entry_learned |
8 |
SrcZoneService Entry Learned |
|
port_pkt_sent |
8 |
Inbound Packets Forwarded |
|
port_bytes_sent |
8 |
Inbound Bytes Forwarded |
|
exceed_drop_brate_src |
8 |
Src KiBit Rate Exceeded |
|
rate_type0_exceed_drop |
8 |
ICMP Type Dst Rate 1 Dropped |
|
src_hw_drop_inserted |
8 |
Src Hardware Drop Rules Inserted |
|
rate_type1_exceed_bl |
8 |
ICMP Type Dst Rate 2 Blacklisted |
|
rate_type2_exceed |
8 |
ICMP Type Dst Rate 3 Exceeded |
|
src_frag_drop |
8 |
Src Fragmented Packets Dropped |
|
port_kbit_rate_exceed |
8 |
KiBit Rate Exceeded |
|
src_rate_type2_exceed_drop |
8 |
ICMP Type Src Rate 3 Dropped |
|
sflow_internal_samples_packed |
8 |
Sflow Internal Samples Packed |
|
rate_type0_exceed |
8 |
ICMP Type Dst Rate 1 Exceeded |
|
type |
8 |
ICMP Type |
|
frag_rcvd |
8 |
Fragmented Packets Received |
|
wildcard_bl |
8 |
ICMP Type Wildcard Blacklisted |
|
icmpv4_rfc_undef_drop |
8 |
ICMPv4 RFC Undef Type Dropped |
|
outbound_port_bytes_drop |
8 |
Outbound Bytes Dropped |
|
secondary_port_hit |
8 |
Per Addr-Port Hit |
|
outbound_port_pkt_sent |
8 |
Outbound Packets Forwarded |
|
sflow_external_packets_sent |
8 |
Sflow External Packets Sent |
|
bl |
8 |
Dst Blacklisted |
|
current_es_level |
8 |
Current Escalation Level |
|
rate_type1_exceed_drop |
8 |
ICMP Type Dst Rate 2 Dropped |
|
exceed_action_tunnel |
8 |
Exceed Action: Tunnel |
|
exceed_drop_brate_src_pkt |
8 |
Src KiBit Rate Exceeded Count |
|
type_deny_drop |
8 |
ICMP Type Dropped |
|
wildcard_deny_drop |
8 |
ICMP Type Wildcard Dropped |
|
outbound_port_rcvd |
8 |
Outbound Packets Received |
|
src_rate_type1_exceed_bl |
8 |
ICMP Type Src Rate 2 Blacklisted |
|
outbound_port_bytes |
8 |
Outbound Bytes Received |
|
exceed_drop_prate_src |
8 |
Src Pkt Rate Exceeded |
|
secondary_port_kbit_rate_exceed |
8 |
Per Addr-Port KiBit Rate Exceeded |
|
port_rcvd |
8 |
Inbound Packets Received |
|
sflow_external_samples_packed |
8 |
Sflow External Samples Packed |
|
port_src_escalation |
8 |
Src Escalation |
|
src_drop |
8 |
Src Packets Dropped |
|
port_bytes |
8 |
Inbound Bytes Received |
|
src_rate_type1_exceed_drop |
8 |
ICMP Type Src Rate 2 Dropped |
|
sflow_internal_packets_sent |
8 |
Sflow Internal Packets Sent |
|
src_rate_type1_exceed |
8 |
ICMP Type Src Rate 2 Exceeded |
|
frag_timeout |
8 |
Fragmented Packets Timeout |
|
wildcard |
8 |
ICMP Type Wildcard |
|
src_rate_type2_exceed_bl |
8 |
ICMP Type Src Rate 3 Blacklisted |
|
frag_drop |
8 |
Fragmented Packets Dropped |
|
port_drop |
8 |
Inbound Packets Dropped |
|
rate_type0_exceed_bl |
8 |
ICMP Type Dst Rate 1 Blacklisted |
|
src_rate_type0_exceed_bl |
8 |
ICMP Type Src Rate 1 Blacklisted |
|
type_bl |
8 |
ICMP Type Blacklisted |
|
dst_hw_drop_removed |
8 |
Dst Hardware Drop Rules Removed |
stats other-zone-ipproto¶
Counter |
Size |
Description |
|
---|---|---|---|
filter_none_match |
8 |
Filter No Match |
|
secondary_port_kbit_rate_exceed_pkt |
8 |
Per Addr-Port KiBit Rate Exceeded Count |
|
filter3_match |
8 |
Filter3 Match |
|
sflow_external_samples_packed |
8 |
Sflow External Samples Packed |
|
src_filter3_match |
8 |
Src Filter3 Match |
|
outbound_port_drop |
8 |
Outbound Packets Dropped |
|
secondary_port_pkt_rate_exceed |
8 |
Per Addr-Port Packet Rate Exceeded |
|
src_filter2_match |
8 |
Src Filter2 Match |
|
src_filter_action_whitelist |
8 |
Src Filter Action Whitelist |
|
port_bytes_drop |
8 |
Inbound Bytes Dropped |
|
exceed_drop_prate_src |
8 |
Src Pkt Rate Exceeded |
|
outbound_port_bytes_sent |
8 |
Outbound Bytes Forwarded |
|
dst_hw_drop |
8 |
Dst Hardware Packets Dropped |
|
src_zone_service_entry_learned |
8 |
SrcZoneService Entry Learned |
|
filter_total_not_match |
8 |
Filter Not Matched on Pkt |
|
filter4_match |
8 |
Filter4 Match |
|
no_policy_class_list_match |
8 |
No Policy Class-list Match |
|
src_filter_action_default_pass |
8 |
Src Filter Action Default Pass |
|
src_zone_service_entry_aged |
8 |
SrcZoneService Entry Aged |
|
src_filter_none_match |
8 |
Src Filter No Match |
|
port_bytes_sent |
8 |
Inbound Bytes Forwarded |
|
exceed_drop_brate_src |
8 |
Src KiBit Rate Exceeded |
|
src_hw_drop_inserted |
8 |
Src Hardware Drop Rules Inserted |
|
src_frag_drop |
8 |
Src Fragmented Packets Dropped |
|
port_kbit_rate_exceed_pkt |
8 |
KiBit Rate Exceeded Count |
|
port_kbit_rate_exceed |
8 |
KiBit Rate Exceeded |
|
sflow_internal_packets_sent |
8 |
Sflow Internal Packets Sent |
|
src_filter4_match |
8 |
Src Filter4 Match |
|
sflow_internal_samples_packed |
8 |
Sflow Internal Samples Packed |
|
secondary_port_kbit_rate_exceed |
8 |
Per Addr-Port KiBit Rate Exceeded |
|
filter_action_default_pass |
8 |
Filter Action Default Pass |
|
filter_action_whitelist |
8 |
Filter Action Whitelist |
|
port_src_bl |
8 |
Src Blacklisted |
|
frag_timeout |
8 |
Fragmented Packets Timeout |
|
outbound_port_bytes_drop |
8 |
Outbound Bytes Dropped |
|
secondary_port_hit |
8 |
Per Addr-Port Hit |
|
outbound_port_pkt_sent |
8 |
Outbound Packets Forwarded |
|
sflow_external_packets_sent |
8 |
Sflow External Packets Sent |
|
bl |
8 |
Dst Blacklisted |
|
current_es_level |
8 |
Current Escalation Level |
|
src_filter_total_not_match |
8 |
Src Filter Not Matched on Pkt |
|
filter_action_drop |
8 |
Filter Action Drop |
|
filter1_match |
8 |
Filter1 Match |
|
src_hw_drop_removed |
8 |
Src Hardware Drop Rules Removed |
|
filter_auth_fail |
8 |
Filter Auth Failed |
|
exceed_action_tunnel |
8 |
Exceed Action: Tunnel |
|
exceed_drop_brate_src_pkt |
8 |
Src KiBit Rate Exceeded Count |
|
src_filter1_match |
8 |
Src Filter1 Match |
|
filter_action_blacklist |
8 |
Filter Action Blacklist |
|
port_pkt_rate_exceed |
8 |
Packet Rate Exceeded |
|
port_pkt_sent |
8 |
Inbound Packets Forwarded |
|
outbound_port_rcvd |
8 |
Outbound Packets Received |
|
filter5_match |
8 |
Filter5 Match |
|
outbound_port_bytes |
8 |
Outbound Bytes Received |
|
src_filter_auth_fail |
8 |
Src Filter Auth Failed |
|
port_rcvd |
8 |
Inbound Packets Received |
|
src_filter5_match |
8 |
Src Filter5 Match |
|
port_src_escalation |
8 |
Src Escalation |
|
src_drop |
8 |
Src Packets Dropped |
|
port_bytes |
8 |
Inbound Bytes Received |
|
dst_hw_drop_inserted |
8 |
Dst Hardware Drop Rules Inserted |
|
frag_rcvd |
8 |
Fragmented Packets Received |
|
src_filter_action_blacklist |
8 |
Src Filter Action Blacklist |
|
filter2_match |
8 |
Filter2 Match |
|
frag_drop |
8 |
Fragmented Packets Dropped |
|
port_drop |
8 |
Inbound Packets Dropped |
|
src_filter_action_drop |
8 |
Src Filter Action Drop |
|
dst_hw_drop_removed |
8 |
Dst Hardware Drop Rules Removed |
operational data¶
Counter |
Size |
Description |
|
---|---|---|---|
app-stat |
flag |
app-stat |
|
black-listed |
flag |
black-listed |
|
authenticated |
flag |
authenticated |
|
overflow-policy |
flag |
overflow-policy |
|
class-list |
string |
class-list |
|
entry-displayed-count |
number |
entry-displayed-count |
|
subnet-ip-addr |
ipv4-cidr |
subnet-ip-addr |
|
exceeded |
flag |
exceeded |
|
ddos_entry_list |
ddos_entry_list |
||
service-displayed-count |
number |
service-displayed-count |
|
white-listed |
flag |
white-listed |
|
sources |
flag |
sources |
|
hw-blacklisted |
flag |
hw-blacklisted |
|
ipv6 |
ipv6-address |
ipv6 |
|
sources-all-entries |
flag |
sources-all-entries |
|
indicator-detail |
flag |
indicator-detail |
|
level |
flag |
level |
|
subnet-ipv6-addr |
ipv6-address-plen |
subnet-ipv6-addr |
|
indicators |
flag |
indicators |