36-26
Cisco 7600 Series Router Cisco IOS Software Configuration Guide, Release 12.2SX
OL-4266-08
Chapter 36 Configuring Denial of Service Protection
DoS Protection Configuration Guidelines and Restrictions
Errors
MAC/IP length inconsistencies : 0
Short IP packets received : 0
IP header checksum errors : 0
TTL failures : 0
<----------------- TTL counters
MTU failures : 0
<------------------MTU failure counters
Total packets L3 Switched by all Modules: 25433414 @ 24 pps
Monitoring Dropped Packets Using VACL Capture
The VACL capture feature allows you to direct traffic to ports configured to forward captured traffic. The
capture action sets the capture bit for the forwarded packets so that ports with the capture function
enabled can receive the packets. Only forwarded packets can be captured.
You can use VACL capture to assign traffic from each VLAN to a different interface.
VACL capture does not allow you to send one type of traffic, such as HTTP, to one interface and another type
of traffic, such as DNS, to another interface. Also, VACL capture granularity is only applicable to traffic
switched locally; you cannot preserve the granularity if you direct traffic to a remote router.
This example shows how to use VACL capture to capture and forward traffic to a local interface:
Router(config-if)#
switchport capture
Router(config-if)#
switchport capture
allowed vlan add 100
Displaying Rate-Limiter Information
The
show mls rate-limit
command displays information about the configured rate limiters.
The
show mls rate-limit usage
command displays the hardware register that is used by a rate-limiter
type. If the register is not used by any rate-limiter type, Free is displayed in the output. If the register is
used by a rate-limiter type, Used and the rate-limiter type are displayed.
In the command output, the rate-limit status could be one of the following:
•
On indicates that a rate for that particular case has been set.
•
Off indicates that the rate-limiter type has not been configured, and the packets for that case are not
rate limited.
•
On/Sharing indicates that a particular case (not manually configured) is affected by the
configuration of another rate limiter belonging to the same sharing group.
•
A hyphen indicates that the multicast partial-SC rate limiter is disabled.
In the command output, the rate-limit sharing indicates the following information:
•
Whether sharing is static or dynamic
•
Group dynamic sharing codes
To display the configured rate limiters, use the
show mls rate-limit
command:
Router#
show mls rate-limit
Sharing Codes: S - static, D - dynamic
Codes dynamic sharing: H - owner (head) of the group, g - guest of the group
Rate Limiter Type Status Packets/s Burst Sharing
--------------------- ---------- --------- ----- -------
MCAST NON RPF Off - - -
MCAST DFLT ADJ On 100000 100 Not sharing