DAS-3600 Series Ethernet over VDSL Switch CLI Reference Manual
32
S
AFEGUARD
E
NGINE
C
OMMANDS
Periodically, malicious hosts on the network will attack the Switch by utilizing packet flooding (ARP Storm) or other methods.
These attacks may increase the CPU utilization beyond its capability. To alleviate this problem, the Safeguard Engine function
was added to the Switch’s software.
The Safeguard Engine can help the overall operability of the Switch by minimizing the workload of the Switch while the attack is
ongoing, thus making it capable to forward essential packets over its network in a limited bandwidth. When the Switch either (a)
receives too many packets to process or (b) exerts too much memory, it will enter an
Exhausted
mode. When in this mode, the
Switch will perform the following tasks to minimize the CPU usage:
a.
It will limit bandwidth of receiving ARP packets.
b. It will limit the bandwidth of IP packets received by the Switch.
IP packets may also be limited by the Switch by configuring only certain IP addresses to be accepted. This method can be
accomplished through the CPU Interface Filtering mechanism explained in the previous section. Once the user configures these
acceptable IP addresses, other packets containing different IP addresses will be dropped by the Switch, thus limiting the
bandwidth of IP packets. To keep the process moving fast, be sure not to add many conditions on which to accept these acceptable
IP addresses and their packets, this limiting the CPU utilization.
Once in Exhausted mode, the packet flow will decrease by half of the level that caused the Switch to enter Exhausted mode. After
the packet flow has stabilized, the rate will initially increase by 25% and then return to a normal packet flow.
NOTICE:
When the Safeguard Engine is enabled, the Switch will allot bandwidth to various traffic
flows (ARP, IP) using the FFP (Fast Filter Processor) metering table to control the CPU utilization
and limit traffic. This may limit the speed of routing traffic over the network.
The Safeguard Engine commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the
following table.
Command
Parameters
config safeguard_engine
{ state [enable|disable] |utilization { rising <value 20-100> | falling <value 20-100>} |
trap_log [enable|disable] | mode [ strict | fuzzy] }
show safeguard_engine
Each command is listed, in detail, in the following sections.
290
Summary of Contents for DAS-3636
Page 1: ...CLI Reference Manual Product Model DAS 3636 VDSL2 Switch Release 1 00 ...
Page 5: ...PASSWORD RECOVERY PROCEDURE 474 ...
Page 20: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 15 ...
Page 25: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 20 ...
Page 79: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 74 ...
Page 99: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 94 ...
Page 106: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 101 ...
Page 113: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 108 ...
Page 135: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 130 ...
Page 140: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 135 ...
Page 223: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 218 ...
Page 230: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 225 ...
Page 235: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 230 ...
Page 240: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 235 ...
Page 245: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 240 ...
Page 316: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 311 ...
Page 321: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 316 ...
Page 341: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 336 ...
Page 346: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 341 ...
Page 351: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 346 ...
Page 356: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 351 ...
Page 360: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 355 ...
Page 365: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 360 ...
Page 372: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 367 ...
Page 389: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 384 ...
Page 394: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 389 ...
Page 396: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 391 ...
Page 450: ...DAS 3600 Series Ethernet over VDSL Switch CLI Reference Manual 445 ...