Cisco WS-C6506 Software Manual page 434

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Using VACLs in Your Network
Console> (enable) show rate-limit
Configured Rate Limiter Settings:
Rate Limiter Type
-------------------- ------
VACL LOG
ARP INSPECTION
FIB RECEIVE
FIB GLEAN
L3 SEC FEATURES
Console> (enable)
Configuring Rate Limiting on a Per-Port Basis
You can rate limit the number of ARP traffic-inspection packets that are sent to the supervisor engine
CPU on a per-port basis. If the rate exceeds the drop-threshold, the excess packets are dropped (and
counted toward the shutdown-threshold limit). If the rate exceeds the shutdown-threshold, the port
that is specified by mod/port is shut down. By default, both threshold values are 0 (no per-port rate
limiting is applied). The maximum value for both thresholds is 1000 packets-per second (pps).
To rate limit the number of ARP traffic-inspection packets that are sent to the CPU per port, perform this
task in privileged mode:
Task
Step 1
Rate limit the number of ARP traffic-inspection
packets that are sent to the supervisor engine CPU on
a per-port basis.
Step 2
Display the drop and shutdown thresholds.
This example shows how to rate limit the number of ARP traffic-inspection packets that are sent to the
CPU on a per-port basis. The drop-threshold is set to 700, and the shutdown threshold is set to 800 for
port 3/1:
Console> (enable) set port arp-inspection 3/1 drop-threshold 700 shutdown-threshold 800
Drop Threshold=700, Shutdown Threshold=800 set on port 3/1.
Console> (enable)
Console> (enable) show port arp-inspection 3/1
Port
------------------------
3/1
Console> (enable)
Configuring the errdisable-timeout Option for ARP Traffic Inspection
You configure the errdisable-timeout option for ARP traffic inspection by using the set
errdisable-timeout {enable | disable} arp-inspection command. For detailed information on the
errdisable-timeout option, see the
on page
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
15-38
Status
Rate (pps)
-------------- -----
On
2500
On
1000
Off
*
Off
*
Off
*
Drop Threshold Shutdown Threshold
-------------- ------------------
4-12.
Burst
1
1
*
*
*
Command
set port arp-inspection mod/port
drop-threshold packets_per_second
shutdown-threshold packets_per_second
set port arp-inspection mod/port
drop-threshold packets_per_second
set port arp-inspection mod/port
shutdown-threshold packets_per_second
show port arp-inspection {[mod/port] | [mod]}
700
"Configuring a Timeout Period for Ports in errdisable State" section
Chapter 15
Configuring Access Control
800
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents