
4.1 Traffic Suppression Overview
This section describes the traffic suppression function.
The AR1200-S forwards broadcast packets, multicast packets, and unknown unicast packets to
all interfaces in the same VLAN. The preceding types of packets occupy a large number of
system resources and waste bandwidth; therefore, the system forwarding capability and
processing capability deteriorate.
The traffic suppression function can limit the rate of the preceding types of packets to protect
the AR1200-S against attacks of these packets. In addition, the function ensures available
bandwidth and processing capability of the AR1200-S when the network traffic is heavy.
4.2 Traffic Suppression Features Supported by the AR1200-
S
This section describes traffic suppression features supported by the AR1200-S.
Traffic suppression can be configured on Ethernet interfaces of the AR1200-S. You can set the
rate limit in bit/s or pps for broadcast packets, multicast packets, or unknown unicast packets on
an interface.
4.3 Configuring Traffic Suppression
This section describes how to configure traffic suppression.
4.3.1 Establishing the Configuration Task
Before configuring traffic suppression, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the required data. This will help you complete
the configuration task quickly and accurately.
Applicable Environment
When receiving unknown unicast packets, multicast packets, or broadcast packets, the AR1200-
S forwards the packets to all the interfaces except the receive interface because the AR1200-S
cannot determine the outbound interface according to the destination MAC address of packets.
In this case, broadcast storms may occur on the network and the forwarding performance of the
AR1200-S deteriorates. To prevent the AR1200-S from being attacked by heavy traffic and
ensure that the AR1200-S can forward packets in unicast mode, configure traffic suppression
on an interface to limit the rate of incoming broadcast packets, multicast packets, or unknown
unicast packets.
Pre-configuration Tasks
Before configuring traffic suppression, complete the following task:
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
4 Traffic Suppression Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
91