![HP ProCurve 1600M Скачать руководство пользователя страница 320](http://html.mh-extra.com/html/hp/procurve-1600m/procurve-1600m_management-and-configuration-manual_155305320.webp)
Port Traffic Controls
Rate-Limiting
ICMP Rate-Limiting
In IP networks, ICMP (Internet Control Message Protocol) messages are
generated in response to either inquiries or requests from routing and diag
nostic functions. These messages are directed to the applications originating
the inquiries. In unusual situations, if the messages are generated rapidly with
the intent of overloading network circuits, they can threaten network avail
ability. This problem is visible in denial-of-service (DoS) attacks or other
malicious behaviors where a worm or virus overloads the network with ICMP
messages to an extent where no other traffic can get through. (ICMP messages
themselves can also be misused as virus carriers). Such malicious misuses of
ICMP can include a high number of ping packets that mimic a valid source IP
address and an invalid destination IP address (spoofed pings), and a high
number of response messages (such as Destination Unreachable error mes
sages) generated by the network.
ICMP rate-limiting provides a method for limiting the amount of bandwidth
that may be utilized for inbound ICMP traffic on a switch port or trunk. This
feature allows users to restrict ICMP traffic to percentage levels that permit
necessary ICMP functions, but throttle additional traffic that may be due to
worms or viruses (reducing their spread and effect). In addition, ICMP
rate-limiting preserves inbound port bandwidth for non-ICMP traffic.
C a u t i o n
The ICMP protocol is necessary for routing, diagnostic, and error responses
in an IP network. ICMP rate-limiting is primarily used for throttling worm or
virus-like behavior, and should normally be configured to allow one to five
per cent of available inbound bandwidth to be used for ICMP traffic.
This
feature should not be used to remove all ICMP traffic from a network
.
N o t e
ICMP rate-limiting does not throttle non-ICMP traffic. In cases where you want
to throttle both ICMP traffic and all other inbound traffic on a given interface,
you can separately configure both ICMP rate-limiting and all-traffic rate-
limiting.
Beginning with software release K.12.
xx
or later, the all-traffic rate-limiting
command (
rate-limit all)
and the ICMP rate-limiting command (
rate-limit icmp
)
operate differently:
•
All traffic rate-limiting applies to both inbound and outbound traffic,
and can be specified either in terms of a percentage of total bandwidth
or in terms of bits per second;
•
ICMP rate-limiting applies only to inbound traffic, and can only be
specified as a percentage of total bandwidth.
13-10
Содержание ProCurve 1600M
Страница 1: ...Management and Configuration Guide 8200zl ProCurve Switches K 12 XX www procurve com ...
Страница 2: ......
Страница 3: ...ProCurve Series 8200zl Switches September 2007 K 12 xx Management and Configuration Guide ...
Страница 68: ...Using the Menu Interface Where To Go From Here 3 16 ...
Страница 110: ...Using the ProCurve Web Browser Interface Status Reporting Features 5 26 ...
Страница 152: ...Switch Memory and Configuration Multiple Configuration Files 6 42 ...
Страница 192: ...Configuring IP Addressing IP Preserve Retaining VLAN 1 IP Addressing Across Configuration File Downloads 8 24 ...
Страница 220: ...Time Protocols SNTP Messages in the Event Log 9 28 ...
Страница 252: ...Port Status and Configuration Uni Directional Link Detection UDLD 10 32 ...
Страница 282: ...Power Over Ethernet PoE Operation PoE Operating Notes 11 30 ...
Страница 472: ...Redundancy Switch 8212zl Event Log Messages 15 48 ...
Страница 510: ...File Transfers Copying Diagnostic Data to a Remote Host USB Device PC or UNIX Workstation A 38 ...
Страница 584: ...Monitoring and Analyzing Switch Operation Locating a Device B 74 ...
Страница 652: ...Troubleshooting Restoring a Flash Image C 68 ...
Страница 660: ...MAC Address Management Viewing the MAC Addresses of Connected Devices D 8 ...
Страница 666: ...Monitoring Resources When Insufficient Resources Are Available E 6 ...
Страница 670: ...Daylight Savings Time on ProCurve Switches F 4 ...
Страница 688: ...18 Index ...
Страница 689: ......