Based on
13.2.3 Principle of QoS Data Plan
, all packets use strict priorities for queue
scheduling and are mapped to queues based on priorities.
huawei(config)#
queue-scheduler strict-priority
huawei(config)#
cos-queue-map cos0 0 cos1 1 cos2 2 cos3 3 cos4 4 cos5 5 cos6 6
cos7 7
//System default
l
Configure system security policies.
–
Enable deny of service (DoS) anti-attack on the OLT.
1.
Run the
security anti-dos enable
command to globally enable DoS anti-attack.
2.
Run the
security anti-dos control-packet policy
command to configure a
protocol packet processing policy that will be used when a DoS attack occurs.
3.
Run the
security anti-dos control-packet rate
command to configure the
threshold for the rate of sending protocol packets to the CPU.
–
Enable IP address anti-attack on the OLT.
Run the
security anti-ipattack enable
command to enable IP address anti-attack.
l
Configure user security policies.
–
Enable MAC address anti-flapping on the OLT.
Run the
security anti-macduplicate enable
command to enable MAC address anti-
flapping.
–
Enable IP address anti-spoofing on the OLT.
1.
In global config mode, run the
security anti-ipspoofing enable
command to
globally enable IP address anti-spoofing.
2.
Enable IP address anti-spoofing at VLAN level, perform the following operations
to enable IP address anti-spoofing in service profile mode:
a.
Run the
vlan service-profile
command to create a VLAN service profile.
b.
Run the
security anti-ipspoofing enable
command to enable IP address
anti-spoofing at VLAN level.
c.
Run the
commit
command to make the profile configuration take effect.
d.
Run the
quit
command to quit the VLAN service profile mode.
e.
Run the
vlan bind service-profile
command to bind the created VLAN
service profile to a VLAN.
–
The service port level: In global config mode, run the
security anti-ipspoofing
service-port serviceport-id
enable
command to enable IP address anti-spoofing at
the service port level.
----End
12.4.3.6 Configuring E2E Reliability
This topic describes how to configure end-to-end (E2E) protection schemes for the enterprise
private line service which has a high requirement on service reliability.
Context
Reliability covers equipment reliability, upstream networking protection, and downstream
networking protection. For details on reliability data planning, see
.
SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
12 FTTO Configuration(SOHO and SME)
Issue 01 (2014-04-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1243