![Cisco Catalyst Blade 3032 Software Configuration Manual Download Page 659](http://html.mh-extra.com/html/cisco/catalyst-blade-3032/catalyst-blade-3032_software-configuration-manual_67665659.webp)
26-21
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
OL-13270-06
Chapter 26 Configuring Port-Based Traffic Control
Configuring Protocol Storm Protection
Configuring Protocol Storm Protection
•
Understanding Protocol Storm Protection, page 26-21
•
Default Protocol Storm Protection Configuration, page 26-21
•
Enabling Protocol Storm Protection, page 26-22
Understanding Protocol Storm Protection
When a switch is flooded with Address Resolution Protocol (ARP) or control packets, high CPU
utilization can cause the CPU to overload. These issues can occur:
•
Routing protocol can flap because the protocol control packets are not received, and neighboring
adjacencies are dropped.
•
Spanning Tree Protocol (STP) reconverges because the STP bridge protocol data unit (BPDU)
cannot be sent or received.
•
CLI is slow or unresponsive.
Using protocol storm protection, you can control the rate at which control packets are sent to the switch
by specifying the upper threshold for the packet flow rate. The supported protocols are ARP, ARP
snooping, Dynamic Host Configuration Protocol (DHCP) v4, DHCP snooping, Internet Group
Management Protocol (IGMP), and IGMP snooping.
When the packet rate exceeds the defined threshold, the switch drops all traffic arriving on the specified
virtual port for 30 seconds. The packet rate is measured again, and protocol storm protection is again
applied if necessary.
For further protection, you can manually error disable the virtual port, blocking all incoming traffic on
the virtual port. You can manually enable the virtual port or set a time interval for automatic re-enabling
of the virtual port.
Note
Excess packets are dropped on no more than two virtual ports.
Virtual port error disabling is not supported for EtherChannel and Flexlink interfaces.
Default Protocol Storm Protection Configuration
Protocol storm protection is disabled by default. When it is enabled, auto-recovery of the virtual port is
disabled by default.