Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PP8600 - packet rate limiter 1

Status
Not open for further replies.

Brat2

IS-IT--Management
May 6, 2004
51
Hi all,

I want to surpress excesive packet attacks on my Nortel Pasport 8600 switch. Does anyone know if it is possible to rate limit not only broadcast/multicast packets?

thanks in advance,
brat
 
By 'not only bcast/mcast packets' do you mean that you want to limit unicast packets as well?

CP-limit is the way to limit bcast/mcast packets, this CLI command will get you started:
config ethernet 1/1 cp-limit ?

The 8600 can also be configured to limit ARP requests, directed broadcasts, multicast learning, and other things that could be used to DoS the CPU. I'm not sure if you could rate-limit packets to the 8600s IP addresses but I'd bet you could create traffic filters to drop packets from all but a few (known secure) management addresses.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top