configure enhanced-dos-protect rate-limit
ExtremeWare 7.5 Command Reference Guide
861
configure enhanced-dos-protect rate-limit
configure enhanced-dos-protect rate-limit [threshold <threshold> |
drop-probability <drop-probability> | learn-window <learn-window> |
protocol [all | icmp]] ports <portlist>
Description
Configures rate limiting for enhanced denial of service protection.
Syntax Description
Default
The default threshold on Fast Ethernet ports is 100 pkts/learn window.
The default threshold on Gigabyte ports is 100 pkts/learn window.
The default drop-probability is 50 percent.
The default learn-window value is 10 seconds.
Rate limiting is applied by default to ICMP packets.
Usage Guidelines
Use this command to configure the rate-limit threshold, drop probability, learning window, or packet
protocol. To verify settings, use the
show enhanced-dos-protect rate-limit ports <portlist>
command. To remove ports from rate limiting, use the
unconfigure enhanced-dos-protect
rate-limit
command.
Examples
The following command sets the rate limiting threshold on port 3 to 200 packets:
configure enhanced-dos-protect rate-limit threshold 200 ports 3
The following command sets the rate limiting drop probability on port 4 to 60 percent:
configure enhanced-dos-protect rate-limit drop-probability 50 ports 4
threshold
Specifies the number of packets allowed on a given port within the learning window
before the rate limit is applied. The valid value range is 100-1953125. The default on
Fast Ethernet ports is 100 pkts/learn window. The default on Gigabyte ports is 100
pkts/learn window.
drop-probability
Specifies the percentage of slow-path traffic to be dropped per port. The valid range is
0-100 percent. The default value is 50 percent.
learn-window
Specifies the number of seconds for the learning window per port. This value is the
duration of time to be considered to reach the rate limit threshold. The valid range is
5-300 seconds. The default value is 10 seconds.
protocol [all | icmp]
Specifies the protocol packets to which rate limiting is applied. By default, rate limiting
is applied to Internet Control Message Protocol (ICMP) packets.
portlist
Specifies one or more ports or slots and ports. On a modular switch, can be a list of
slots and ports. On a stand-alone switch, can be one or more port numbers. May be
in the form 1, 2, 3-5, 1:*, 1:5, 1:6-1:8.
Summary of Contents for ExtremeWare 7.5
Page 402: ...402 ExtremeWare 7 5 Command Reference Guide VLAN Commands ...
Page 470: ...470 ExtremeWare 7 5 Command Reference Guide QoS Commands ...
Page 490: ...490 ExtremeWare 7 5 Command Reference Guide NAT Commands ...
Page 826: ...826 ExtremeWare 7 5 Command Reference Guide Commands for Status Monitoring and Statistics ...
Page 1090: ...1090 ExtremeWare 7 5 Command Reference Guide Security Commands ...
Page 1386: ...1386 ExtremeWare 7 5 Command Reference Guide Wireless Commands ...
Page 1436: ...1436 ExtremeWare 7 5 Command Reference Guide EAPS Commands ...
Page 1568: ...1568 ExtremeWare 7 5 Command Reference Guide ESRP Commands ...
Page 1844: ...1844 ExtremeWare 7 5 Command Reference Guide IGP Commands ...
Page 1930: ...1930 ExtremeWare 7 5 Command Reference Guide BGP Commands i Series Switches Only ...
Page 2022: ...2022 ExtremeWare 7 5 Command Reference Guide IP Multicast Commands ...
Page 2066: ...2066 ExtremeWare 7 5 Command Reference Guide IPX Commands i Series Platforms Only ...
Page 2082: ...2082 ExtremeWare 7 5 Command Reference Guide ARM Commands BlackDiamond Switch Only ...
Page 2094: ...2094 ExtremeWare 7 5 Command Reference Guide Remote Connect Commands ...
Page 2174: ...2174 ExtremeWare 7 5 Command Reference Guide PoS Commands BlackDiamond Switch Only ...
Page 2372: ...2372 ExtremeWare 7 5 Command Reference Guide LLDP Commands ...
Page 2422: ...2422 ExtremeWare 7 5 Command Reference Guide H VPLS Commands BlackDiamond Switch Only ...
Page 2528: ...2528 ExtremeWare 7 5 Command Reference Guide MPLS Commands BlackDiamond Switch Only ...