NOTE
Packets from different base stations may carry different user VLANs. Ensure that user VLANs are consistent
with the actual ones during configuration.
----End
14.4.8.4 Configuring Congestion Control and Security Policies
This topic describes how to configure global priority-based scheduling policies for queues to
ensure service reliability and configure global security policies to ensure service security.
Context
Congestion control uses queue scheduling technology to map packets sent from the same port
into multiple queues and process packets in each queue based on priority. Congestion control is
recommended.
Security policies cover system security, user security, and service security, which ensure normal
running of services.
NOTE
Enable security features based on service types. For details, see
11.2.7 Principle of Security Data Plan
Procedure
l
Configure queue scheduling.
Based on
13.2.3 Principle of QoS Data Plan
, all packets use strict priorities for queue
scheduling and are mapped to queues based on priorities.
huawei(config)#
queue-scheduler strict-priority
huawei(config)#
cos-queue-map cos0 0 cos1 1 cos2 2 cos3 3 cos4 4 cos5 5 cos6 6
cos7 7
//System default
l
Configure system security.
–
Enable deny of service (DoS) anti-attack on both the OLT and optical network units
(ONUs).
1.
Run the
security anti-dos enable
command to globally enable DoS anti-attack.
2.
Run the
security anti-dos control-packet policy
command to configure a
protocol packet processing policy that will be used when a DoS attack occurs.
3.
Run the
security anti-dos control-packet rate
command to configure the
threshold for the rate of sending protocol packets to the CPU.
–
Enable IP address anti-attack on both the OLT and ONUs.
Run the
security anti-ipattack enable
command to enable IP address anti-attack.
l
Configure user security.
–
Enable MAC address anti-flapping on both the OLT and ONUs.
Run the
security anti-macduplicate enable
command to enable MAC address anti-
flapping.
----End
SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
14 FTTM Configuration (Base Station Access)
Issue 01 (2014-04-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1499