32-3
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
OL-9639-07
Chapter 32 Configuring Control-Plane Security
Understanding Control-Plane Security
The switch automatically allocates 27 control-plane security policers for CPU protection. At system
bootup, it assigns a policer to each port numbered 0 to 26. The policer assigned to a port determines if
the protocol packets arriving on the port are rate-limited or dropped. A policer of 26 means a drop policer
and is a global policer; any traffic type shown as 26 on any port is dropped. A policer of a value of 0 to
Table 32-1
Control-Plane Security Actions on Layer 2 Protocol Packets Received on a UNI or ENI
Protocol
Default
When Feature Is Enabled
When Layer 2
Protocol Tunneling
Is Enabled
1
1.
Layer 2 protocol traffic is rate-limited when Layer 2 protocol tunneling is enabled for any protocol on any port.
STP
Dropped
Rate limited
Note
STP can be enabled only on ENIs.
Rate-limited
RSVD_STP (reserved IEEE
802.1D addresses)
Dropped
When the Ethernet Link Management Interface
(ELMI) is enabled, globally or on a per-port basis
whichever is configured last, a throttle policer is
assigned to a port. When ELMI is disabled (globally or
on a port, whichever is configured last), a drop policer
is assigned to a port.
PVST+
Dropped
–
Rate limited
LACP
Dropped
Rate limited
Note
LACP can be enabled only on ENIs.
Rate limited
PAgP
Dropped
Rate limited
Note
PAgP can be enabled only on ENIs.
Rate limited
IEEE 802.1x
Dropped
Rate limited
–
CDP
Dropped
Rate limited
Note
CDP can be enabled only on ENIs.
Rate limited
LLDP
Dropped
Rate limited
Note
LLDP can be enabled only on ENIs.
Rate limited
DTP
Dropped
–
–
UDLD
Dropped
Rate limited
Rate limited
VTP
Dropped
–
Rate limited
CISCO_L2 (any other Cisco
Layer 2 protocols with the MAC
address 01:00:0c:cc:cc:cc)
Dropped
–
Rate limited if
CDP, DTP, UDLD,
PAGP, or VTP are
Layer 2 tunneled
KEEPALIVE (MAC address,
SNAP encapsulation, LLC, Org
ID, or HDLC packets)
Rate-limited
–
–
Ethernet Connectivity Fault
Management (CFM)
No policer
assigned
When CFM is enabled globally, a throttle policer is
assigned to all ports. When CFM is disabled globally,
a NULL policer is assigned to all ports.
–
Summary of Contents for ME 3400 Series
Page 40: ...Contents xl Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...
Page 44: ...xliv Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 Preface ...
Page 1138: ...Index IN 52 Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...