![Alcatel-Lucent 7950 SR System Management Manual Download Page 32](http://html1.mh-extra.com/html/alcatel-lucent/7950-sr/7950-sr_system-management-manual_2892148032.webp)
CPU Protection
Page 32
7950 SR OS System Management Guide
CPU Protection
SR OS provides several rate limiting mechanisms to protect the CPM/CFM processing
resources of the router:
•
CPU Protection: A centralized rate limiting function that operates on the CPM to limit
traffic destined to the CPUs.
•
Distributed CPU Protection: A control traffic rate limiting protection mechanism for
the CPM/CFM that operates on the line cards (hence ‘distributed’).
CPU protection protects the CPU of the node that it is configured on from a DOS attack by
limiting the amount of traffic coming in from one of its ports and destined to the CPM (to be
processed by its CPU) using a combination of the configurable limits.
Some of the limits are configured globally for the node, and some of the limits are configured
in CPU Protection profiles which are assigned to interfaces.
The following limits are configured globally for the node:
•
link-specific rate — Applies to the link-specific protocol LACP (LAG control).The
rate is a per-link limit (each link in the system will have LACP packets limited to this
rate).
•
port-overall-rate – Applies to all control traffic each port. The rate is a per-port limit
(each port in the system will have control traffic destined to the CPM limited to this
rate).
•
protocol-protection — Blocks network control traffic for unconfigured protocols. If
IS-IS is not configured on an IP interface all IS-IS-related traffic will be dropped and
not reach the CPU.
The following limits are configured within CPU Protection policies (1-255). CPU Protection
policies are created, configured, and then assigned to interfaces.
•
overall-rate — Applies to all control trafficdestined to the CPM (all sources) received
on the interface (only where the policy is applied). This is a per-interface limit.
Control traffic received above this rate will be discarded.
•
per-source-rate — Used to limit the control traffic destined to the CPM from each
individual source. This per-source-rate is only applied when an object (SAP) is
configured with a cpu-protection policy and also with the optional mac-monitoring or
ip-src-monitoring keywords. A source is defined as a
SAP, Source MAC Address
tuple
for mac-monitoring and as a
SAP, Source IP Address
tuples for
ip-src
-monitoring.
Only the DHCP protocol is limited (per source) when the
ip-src
-monitoring keyword
is used.
•
out-profile-rate – Applies to all control traffic destined to the CPM (all sources)
received on the interface (only where the policy is applied). This is a per-interface
Summary of Contents for 7950 SR
Page 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Page 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Page 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Page 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Page 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Page 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Page 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Page 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Page 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Page 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Page 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Page 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Page 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Page 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Page 460: ...Standards and Protocols Page 460 Standards and Protocols...