Security
7950 SR OS System Management Guide
Page 201
monitor. The local monitor may then detect exceeded packets again and make another attempt at allo-
cating dynamic policers.
Once this
policer-name
is referenced by a protocol then this policer will be instantiated for each
“object” that is created and references this DDoS policy. If there is no policer free then the object will
be blocked from being created.
Parameters
policy-name —
Specifies name of the policy.
Values
[32 chars max]
exceed-action
Syntax
exceed-action {discard | hold-down | none}
Context
config>system>security>dist-cpu-protection>policy>local-monitoring-policer
Description
This command controls the action performed upon the extracted control packets when the configured
policer rates are exceeded.
Default
none
Parameters
discard —
Discards packets that are non-conformant.
hold-down seconds —
(optional) When the parameter is specified, it causes the following “hold-
down” behavior.
When SR OS software detects that an enforcement policer has marked or discarded one or more
packets (software may detect this some time after the packets are actually discarded), and an
optional
hold-down
seconds
value has been specified for the
exceed-action
, then the policer will
be set into a “mark-all” or “drop-all” mode that cause the following:
- the policer state to be updated as normal
- all packets to be marked (if the action is “low-priority”) or dropped (action = discard) regardless
of the results of the policing decisions/actions/state.
The
hold-down
is cleared after approximately the configured time in seconds after it was set.
The
hold-down
seconds
option should be selected for protocols that receive more than one
packet in a complete handshake/negotiation (for example, DHCP, PPP).
hold-down
is not
applicable to a local monitoring policer. The “detection-time” will only start after any
hold-
down
is complete. During the
hold-down
(and the detection-time), the policer is considered as in
an “exceed” state. The policer may re-enter the hold-down state if an exceed packet is detected
during the detection-time countdown. The allowed values are [none|1..10080|indefinite].
Values
1-10080 in seconds
none —
no hold-down
Summary of Contents for 7950 SR
Page 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Page 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Page 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Page 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Page 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Page 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Page 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Page 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Page 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Page 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Page 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Page 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Page 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Page 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Page 460: ...Standards and Protocols Page 460 Standards and Protocols...