Pp Configuration - Zte ZXR10 2900E series Configuration Manual

Easy-maintenance secure switch
Hide thumbs Also See for ZXR10 2900E series:
Table of Contents

Advertisement

5.35 PP Configuration

PP Overview
Protocol Protect (PP) maintains and monitors the rate of packets forwarded to the CPU,
thus preventing viruses or spiteful attacks to the switch. In this way, the switch provides
self-protection ability and ensures network security.
PP takes the following measures: limiting the rates of related services, filtering unsuitable
packets, sending alarms when there are packets sent at an abnormal rate, and reminding
NMS that there may be packets attacking the CPU.
To enhance flexibility and compatibility of the switch, PP provides the function of configuring
priority users for the protocol packets sent by the switch.
Configuring PP
The PP configuration includes the following commands:
Command
zte(cfg)#
<1-128> src-mac <HH.HH.HH.HH.HH.HH> mask
<HH.HH.HH.HH.HH.HH>
zte(cfg)#
disable}
zte(cfg)#
me}<0-18000>
zte(cfg)#
zte(cfg)#
>|default}
zte(cfg)#
zte(cfg)#
<portlist>
zte(cfg)#
<portlist>]
zte(cfg)#
<1-128>]
zte(cfg)#
show protocol-protect statistic [port <portlist>] (all configuration
modes)
show protocol-protect limit (all configuration modes)
SJ-20130731155059-002|2013-11-27 (R1.0)
create protocol-protect mac-drop rule
set protocol-protect alarm port <portlist>{enable |
set protocol-protect alarm port <portlist>{protocol-na
set protocol-protect limit {group-name}<0-800>
set protocol-protect priority{protocol-name|all}{<0-7
set protocol-protect mac-drop {disable | enable}
set protocol-protect mac-drop rule <1-128> bind port
clear protocol-protect mac-drop counter [port
clear protocol-protect mac-drop port <portlist>[rule
clear protocol-protect mac-drop rule [<1-128>]
Chapter 5 Service Configuration
5-133
ZTE Proprietary and Confidential
Function
Creates a mac drop rule.
Enables or disables the PP alarm
function on a port.
Sets PP 30 second-protocol alarm
threshold.
Sets the rate limit of sending
packets to the CPU.
Sets PP protocol priority.
Enables the mac drop function.
Binds the mac drop rule with the
port.
Clears the number of messages
dropped by the mac drop function.
Clears the mac drop rules for
specified or all ports.
Clears specified mac drop rules.
Displays statistics information of
protocol packet alarms on a PP
port.
Displays PP rate limit information.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents