When the packet rate exceeds the defined threshold, the switch drops all traffic arriving on the specified virtual
port for 30 seconds. The packet rate is measured again, and protocol storm protection is again applied if
necessary.
For further protection, you can manually error disable the virtual port, blocking all incoming traffic on the
virtual port. You can manually enable the virtual port or set a time interval for automatic re-enabling of the
virtual port.
Excess packets are dropped on no more than two virtual ports.
Virtual port error disabling is not supported for EtherChannel and Flexlink interfaces
Note
Default Protocol Storm Protection Configuration
Protocol storm protection is disabled by default. When it is enabled, auto-recovery of the virtual port is disabled
by default.
How to Configure Protocol Storm Protection
Enabling Protocol Storm Protection
SUMMARY STEPS
1.
enable
2.
configure terminal
3.
psp
{
arp
|
dhcp
|
igmp
} pps
value
4.
errdisable detect cause psp
5.
errdisable recovery interval time
6.
end
7.
show psp config
{
arp
|
dhcp
|
igmp
}
DETAILED STEPS
Purpose
Command or Action
Enables privileged EXEC mode. Enter your password if prompted.
enable
Step 1
Example:
Switch>
enable
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
OL-29048-01
435
Configuring Port-Based Traffic Control
Default Protocol Storm Protection Configuration