![Alcatel-Lucent 7950 SR Скачать руководство пользователя страница 203](http://html1.mh-extra.com/html/alcatel-lucent/7950-sr/7950-sr_system-management-manual_2892148203.webp)
Security
7950 SR OS System Management Guide
Page 203
• pppoe-pppoa: includes PADx, LCP, PAP/CHAP and NCPs
• all-unspecified: a special ‘protocol’. When configured, this treats all extracted control packets
that are not explicitly created in the dist-cpu-protection policy as a single aggregate flow (or “vir-
tual protocol”). It lumps together “all the rest of the control traffic” to allow it to be rate limited
as one flow. It includes all control traffic of all protocols that are extracted and sent to the CPM
(even protocols that cannot be explicitly configured with the distributed cpu protection feature).
Control packets that are both forwarded and copied for extraction are not included. If an operator
later explicitly configures a protocol, then that protocol is suddenly no longer part of the “all-
unspecified” flow. The “all-unspecified” protocol must be explicitly configured in order to oper-
ate.
“no protocol x” means packets of protocol x are not monitored and not enforced (although they do
count in the fp protocol queue) on the objects to which this dist-cpu-protection policy is assigned,
although the packets will be treated as part of the all-unspecified protocol if the all-unspecified proto-
col is created in the policy.
Default
none
Parameters
names —
Signifies protocol name.
Values
arp|dhcp|http-redirect|icmp|igmp|mld|ndis|pppoe-pppoa|all-unspecified|mpls-
ttl|bfd-cpm|bgp|eth-cfm|isis|ldp|ospf+|pim|rsvp.
enforcement
Syntax
enforcement {static policer-name | dynamic {mon-policer-name | local-mon-bypass}}
Context
config>system>security>dist-cpu-protection>policy>protocols
Description
This command configures the enforcement method for the protocol.
Default
dynamic local-mon-bypass
Parameters
static —
the protocol is always enforced using a static-policer. Multiple protocols can reference the
same static-policer. Packets of protocols that are statically enforced bypass any local monitors.
policer name —
Specifies the name is a static-policer.
dynamic —
A specific enforcement policer for this protocol for this SAP/object is instantiated when
the associated local-monitoring-policer is determined to be in a non-conformant state (at the end
of a minimum monitoring time of 60 seconds to reduce thrashing).
mon-policer-name —
Specifies which local-monitoring-policer to use
local-mon-bypass —
This parameter is used to not include packets from this protocol in the local
monitoring function, and when the local-monitor “trips”, do not instantiate a dynamic
enforcement policer for this protocol.
Содержание 7950 SR
Страница 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Страница 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Страница 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Страница 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Страница 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Страница 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Страница 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Страница 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Страница 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Страница 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Страница 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Страница 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Страница 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Страница 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Страница 460: ...Standards and Protocols Page 460 Standards and Protocols...