14-18
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 14 Value-Added Services (VAS) Traffic Forwarding
Interactions Between VAS Traffic Forwarding and Other Cisco SCE Platform Features
Interactions Between VAS Traffic Forwarding and Other Cisco
SCE Platform Features
•
Incompatible Cisco SCE Platform Features, page 14-18
•
VAS Traffic Forwarding and DDoS Processing, page 14-18
•
VAS Traffic Forwarding and Bandwidth Management, page 14-19
Incompatible Cisco SCE Platform Features
There are certain Cisco SCE platform features that are incompatible with VAS traffic forwarding. Before
enabling VAS traffic forwarding, it is the responsibility of the user to make sure that no incompatible
features or modes are configured.
There are certain Cisco SCE platform features that are incompatible with VAS traffic forwarding. Before
you enable VAS traffic forwarding, you must ensure that no incompatible features or modes are
configured.
The features and modes listed below cannot coexist with VAS mode:
•
Line-card connection modes—receive-only, receive-only-cascade, inline-cascade
•
Link mode other than forwarding
•
All link encapsulation protocols, including VLAN, MPLS, and L2TP
•
Traffic mirroring (see
“Intelligent Traffic Mirroring” section on page 14-36
)
Note
If VAS forwarding is enabled, Cisco SCE devices do not forward VLAN-tagged subscriber traffic
received from subscriber side and network side traffic ports to the VAS interface for processing.
VAS Traffic Forwarding and DDoS Processing
VAS traffic forwarding has minor effects on the distributed denial of service (DDoS) mechanisms.
•
Specific IP DDoS Attack Detection, page 14-18
•
Specific IP Attack Filter, page 14-18
Specific IP DDoS Attack Detection
The specific IP DDoS mechanism uses software counters. The second pass VAS packets do not reach the
Service Control Operating System (SCOS), so they are not counted twice.
Network-side packets are handled by the attack-detector in the first pass, when they open a flow, so they
are also not counted twice.
Specific IP Attack Filter
The behavior depends on the action configured.
•
Report only—VAS is not affected.