CPU Queue
Weights
Rate (pps)
Protocol
11
32
300
PIM, IGMP, MSDP, MLD
Catch-All Entry for IPv6 Packets
Dell Networking OS currently supports configuration of IPv6 subnets greater than /64 mask length, but the
agent writes it to the default LPM table where the key length is 64 bits. The device supports table to store up
to 256 subnets of maximum of /128 mask lengths. This can be enabled and agent can be modified to update
the /128 table for mask lengths greater than /64. This will restrict the subnet sizes to required optimal level
which would avoid these NDP attacks. The IPv6 stack already supports handling of >/64 subnets and doesn’t
require any additional work. The default catch-all entry is put in the LPM table for IPv4 and IPv6. If this is
included for IPv6, you can disable this capability by using the
no ipv6 unknown-unicast
command.
Typically, the catch-all entry in LPM table is used for soft forwarding and generating ICMP unreachable
messages to the source. If this is in place then irrespective of whether it is </64 subnet or >/64 subnet, it
doesn’t have any effect as there would always be LPM hit and traffic are sent to CPU.
Unknown unicast L3 packets are terminated to the CPU CoS queue which is also shared for other types of
control-plane packets like ARP Request, Multicast traffic, L3 packets with Broadcast MAC address. The catch-
all route poses a risk of overloading the CPU with unknown unicast packets. This CLI knob to turn off the
catch-all route is of use in networks where the user does not want to generate Destination Unreachable
messages and have the CPU queue’s bandwidth available for higher priority control-plane traffic.
Configuring CoPP for OSPFv3
You can create an IPv6 ACL for control-plane traffic policing for OSPFv3, in addition to the CoPP support for
VRRPv3, BGPv6, and ICMPv6. You can use the
ipv6 access-list
name
cpu-qos permit ospfv3
or the
ipv6 access-list
name
cpu-qos ospfv3
command to allow CoPP traffic for OSPFv3. The control
plane management support for IPv6 ICMPv6 packets is enhanced to enable more number of CPU queues on
port to be available and other COPP improvements have been implemented.
To configure control-plane policing, perform the following:
1
Create an IPv6 ACL for control-plane traffic policing for ospfv3.
CONFIGURATION mode
Dell(conf)#ipv6 access-list ospfv3 cpu-qos
Dell(conf-ipv6-acl-cpuqos)#permit ospf
2 Create a QoS input policy for the router and assign the policing.
CONFIGURATION mode
Dell(conf)#qos-policy-input ospfv3_rate cpu-qos
Dell(conf-in-qos-policy-cpuqos)#rate-police 1500 16 peak 1500 16
3 Create a QoS class map to differentiate the control-plane traffic and assign to the ACL.
CONFIGURATION mode
Dell(conf)#class-map match-any ospfv3 cpu-qos
Control Plane Policing (CoPP)
290
Summary of Contents for S4048T
Page 1: ...Dell Configuration Guide for the S4048T ON System 9 10 0 1 ...
Page 98: ... saveenv 7 Reload the system uBoot mode reset Management 98 ...
Page 113: ...Total CFM Pkts 10303 CCM Pkts 0 LBM Pkts 0 LTM Pkts 3 LBR Pkts 0 LTR Pkts 0 802 1ag 113 ...
Page 411: ...mode transit no disable Force10 Resilient Ring Protocol FRRP 411 ...
Page 590: ...Figure 67 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 590 ...
Page 646: ...Figure 87 Configuring Interfaces for MSDP Multicast Source Discovery Protocol MSDP 646 ...
Page 647: ...Figure 88 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 647 ...
Page 653: ...Figure 91 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 653 ...
Page 654: ...Figure 92 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 654 ...
Page 955: ...Figure 119 Single and Double Tag First byte TPID Match Service Provider Bridging 955 ...