32-5
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
OL-9639-07
Chapter 32 Configuring Control-Plane Security
Configuring Control-Plane Security
PAGP 10 26 0
VTP 11 26 0
CISCO_L2 12 22 0
KEEPALIVE 13 22 0
CFM 14 255 0
SWITCH_MAC 15 26 0
SWITCH_ROUTER_MAC 16 26 0
SWITCH_IGMP 17 22 0
SWITCH_L2PT 18 22 0
This example shows the default policers assigned to NNIs. Most protocols have no policers assigned to
NNIs. A value of 255 means that no policer is assigned to the port for the protocol.
Switch #
show platform policer cpu interface gigabitethernet 0/1
Policers assigned for CPU protection
===================================================================
Feature Policer Physical Asic
Index Policer Num
===================================================================
Gi0/1
STP 1 255 0
LACP 2 255 0
8021X 3 255 0
RSVD_STP 4 255 0
PVST_PLUS 5 255 0
CDP 6 255 0
LLDP 7 255 0
DTP 8 255 0
UDLD 9 255 0
PAGP 10 255 0
VTP 11 255 0
CISCO_L2 12 255 0
KEEPALIVE 13 255 0
CFM 14 255 0
SWITCH_MAC 15 255 0
SWITCH_ROUTER_MAC 16 255 0
SWITCH_IGMP 17 255 0
SWITCH_L2PT 18 255 0
Configuring Control-Plane Security
CPU protection is enabled by default and CPU policers are pre-allocated. You can disable CPU
protection by entering the
no policer cpu uni all
global configuration command or reenable it by
entering the
policer cpu uni all
global configuration command. When you disable or enable CPU
protection, you must reload the switch by entering the
reload
privileged EXEC command before the
configuration takes effect.
When CPU protection is enabled, you can configure only 45 policers per port. Disabling CPU protection
allows you to configure up to 64 policers per port. Note these limitations when you disable CPU
protection:
•
When CPU protection is disabled, you can configure a maximum of 63 policers per port (62 on every
4th port) for user-defined classes and one for class-default.
•
On Cisco ME 3400G-12CS switches, due to hardware limitations, you can attach 64 per-port,
per-VLAN policers to a maximum of 6 ports. If you attempt to attach more than 6 per-port per
VLAN 64-policer policy maps, the attachment fails with a
VLAN labels exceeded
error message.
Содержание ME 3400 Series
Страница 40: ...Contents xl Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...
Страница 44: ...xliv Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 Preface ...
Страница 1138: ...Index IN 52 Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...