1-40
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] stp tc-protection enable
stp tc-protection threshold
Syntax
stp tc-protection threshold number
undo stp tc-protection threshold
View
System view
Parameters
number
: Maximum number of times that a switch can remove the MAC address table and ARP entries
within each 10 seconds, in the range of 1 to 255.
Description
Use the
stp tc-protection threshold
command to set the maximum number of times that a switch can
remove the MAC address table and ARP entries within each 10 seconds.
Use the
undo stp tc-protection threshold
command to restore the default.
Normally, a switch removes the MAC address table and ARP entries upon receiving a TC-BPDU. If a
malicious user sends large amount of TC-BPDUs to a switch in a short period, the switch may be busy
in removing the MAC address table and ARP entries, which may affect spanning tree calculation,
occupy a large amount of bandwidth and increase switch CPU utilization.
With the TC-BPDU attack guard function enabled, a switch performs a removing operation upon
receiving a TC-BPDU and triggers a timer (set to 10 seconds by default) at the same time. Before the
timer expires, the switch only performs the removing operation for limited times (up to six times by
default) regardless of the number of the TC-BPDUs it receives. Such a mechanism prevents a switch
from being busy in removing the MAC address table and ARP entries.
You can use the
stp tc-protection threshold
command to set the maximum times for a switch to
remove the MAC address table and ARP entries in a specific period. When the number of the
TC-BPDUs received within a period is less than the maximum times, the switch performs a removing
operation upon receiving a TC-BPDU. After the number of the TC-BPDUs received reaches the
maximum times, the switch stops performing the removing operation. For example, if you set the
maximum times for a switch to remove the MAC address table and ARP entries to 100 and the switch
receives 200 TC-BPDUs in the period, the switch removes the MAC address table and ARP entries for
only 100 times within the period.
Examples
# Set the maximum times for a switch to remove the MAC address table and ARP entries within 10
seconds to 5.
<Sysname>system-view
System View: return to User View with Ctrl+Z.
[Sysname] stp tc-protection threshold 5
Содержание 5500-EI PWR
Страница 43: ...2 6...
Страница 76: ...1 17...
Страница 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46...
Страница 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast...
Страница 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23...
Страница 519: ...iii...
Страница 597: ...2 2 security policy server 192 168 0 1 user name format without domain...
Страница 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static...
Страница 663: ...4 3 Sysname resilient arp interface vlan interface 2...
Страница 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008...
Страница 1111: ...ii xmodem get 3 18...
Страница 1314: ...A 44 Z...