Security
7950 SR OS System Management Guide
Page 195
port-overall-rate
Syntax
port-overall-rate packet-rate-limit
no port-overall-rate
Context
config>sys>security>cpu-protection
Description
This command configures a per-port overall rate limit for CPU protection.
Parameters
packet-rate-limit —
Specifies an overall per-port packet arrival rate limit in packets per second.
Values
1 — 65535, max (indicates no limit)
protocol-protection
Syntax
protocol-protection
[
allow-sham-links
]
no protocol-protection
Context
config>sys>security>cpu-protection
Description
This command causes the network processor on the CPM to discard all packets received for protocols
that are not configured on the particular interface. This helps mitigate DoS attacks by filtering invalid
control traffic before it hits the CPU. For example, if an interface does not have IS-IS configured,
then protocol protection will discard any IS-IS packets received on that interface.
Default
no protocol-protection
Parameters
allow-sham-links —
Allows sham links. As OSPF sham links form an adjacency over the MPLS-
VPRN backbone network, when protocol-protection is enabled, the tunneled OSPF packets to be
received over the backbone network must be explicitly allowed.
cpu-protection
Syntax
cpu-protection policy-id
no cpu-protection
Context
config>router>interface
config>service>ies>interface
config>service>vprn>interface
config>service>vprn>network-interface
Description
Use this command to apply a specific CPU protection policy to the associated interface. For these
interface types, the per-source rate limit is not applicable.
If no CPU-protection policy is assigned to an interface, then the default policy is used to limit the
overall-rate. The default policy is policy number 254 for access interfaces, 255 for network interfaces.
The
no
form of the command reverts to the default values.
Default
cpu-protection 254 (for access interfaces)
Содержание 7950 SR
Страница 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Страница 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Страница 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Страница 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Страница 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Страница 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Страница 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Страница 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Страница 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Страница 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Страница 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Страница 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Страница 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Страница 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Страница 460: ...Standards and Protocols Page 460 Standards and Protocols...