![Alcatel-Lucent 7950 SR Скачать руководство пользователя страница 37](http://html1.mh-extra.com/html/alcatel-lucent/7950-sr/7950-sr_system-management-manual_2892148037.webp)
Security
7950 SR OS System Management Guide
Page 37
Distributed CPU Protection (DCP)
SR OS provides several rate limiting mechanisms to protect the CPM/CFM processing
resources of the router:
•
CPU Protection: A centralized rate limiting function that operates on the CPM to limit
traffic destined to the CPUs. This feature is described elsewhere in this guide.
•
Distributed CPU Protection: A control traffic rate limiting protection mechanism for
the CPM/CFM that operates on the line cards (hence ‘distributed’).
Distributed CPU Protection (DCP) offers a powerful per-protocol-per-object (examples of
objects are SAPs and network interfaces) rate limiting function for control protocol traffic that
is extracted from the data path and sent to the CPM. The DCP function is implemented on the
router line cards that allows for high levels of scaling and granularity of control.
The DCP rate limiting is configured via policies that are applied to objects (for example,
SAPs).
The basic types of policers in DCP are:
•
Enforcement Policers — An instance of a policer that is policing a flow of packets
comprised of a single (or small set of) protocols(s) arriving on a single object (for
example, SAP). Enforcement policers perform a configurable action (for example,
discard) on packets that exceed configured rate parameters. There are two basic sub-
types of enforcement policers:
Static policers — always instantiate.
Dynamic policers — only instantiated (allocated from a free pool of dynamic
policers) when a local monitor detects non-conformance for a set of protocols on
a specific object.
•
Local Monitors — A policer that is primarily used to measure the conformance of a
flow comprised of multiple protocols arriving on a single object. Local monitors are
used as a trigger to instantiate dynamic policers.
The use of dynamic policers reduces the number of policers required to effectively monitor
and control a set of protocols across a large set of objects since the per-protocol-per-object
dynamic policers are only instantiated when an attack or misconfiguration occurs, and they are
only instantiated for the affected objects.
Содержание 7950 SR
Страница 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Страница 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Страница 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Страница 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Страница 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Страница 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Страница 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Страница 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Страница 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Страница 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Страница 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Страница 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Страница 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Страница 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Страница 460: ...Standards and Protocols Page 460 Standards and Protocols...