Configure Enhanced-Dos-Protect Rate-Limit - Extreme Networks ExtremeWare Command Reference Manual

Version 7.5
Hide thumbs Also See for ExtremeWare:
Table of Contents

Advertisement

configure enhanced-dos-protect rate-limit

configure enhanced-dos-protect rate-limit [threshold <threshold> |
drop-probability <drop-probability> | learn-window <learn-window> |
protocol [all | icmp]] ports <portlist>
Description
Configures rate limiting for enhanced denial of service protection.
Syntax Description
threshold
drop-probability
learn-window
protocol [all | icmp]
portlist
Default
The default threshold on Fast Ethernet ports is 100 pkts/learn window.
The default threshold on Gigabyte ports is 100 pkts/learn window.
The default drop-probability is 50 percent.
The default learn-window value is 10 seconds.
Rate limiting is applied by default to ICMP packets.
Usage Guidelines
Use this command to configure the rate-limit threshold, drop probability, learning window, or packet
protocol. To verify settings, use the
command. To remove ports from rate limiting, use the
rate-limit
Examples
The following command sets the rate limiting threshold on port 3 to 200 packets:
configure enhanced-dos-protect rate-limit threshold 200 ports 3
The following command sets the rate limiting drop probability on port 4 to 60 percent:
configure enhanced-dos-protect rate-limit drop-probability 50 ports 4
ExtremeWare 7.5 Command Reference Guide
Specifies the number of packets allowed on a given port within the learning window
before the rate limit is applied. The valid value range is 100-1953125. The default on
Fast Ethernet ports is 100 pkts/learn window. The default on Gigabyte ports is 100
pkts/learn window.
Specifies the percentage of slow-path traffic to be dropped per port. The valid range is
0-100 percent. The default value is 50 percent.
Specifies the number of seconds for the learning window per port. This value is the
duration of time to be considered to reach the rate limit threshold. The valid range is
5-300 seconds. The default value is 10 seconds.
Specifies the protocol packets to which rate limiting is applied. By default, rate limiting
is applied to Internet Control Message Protocol (ICMP) packets.
Specifies one or more ports or slots and ports. On a modular switch, can be a list of
slots and ports. On a stand-alone switch, can be one or more port numbers. May be
in the form 1, 2, 3-5, 1:*, 1:5, 1:6-1:8.
show enhanced-dos-protect rate-limit ports <portlist>
command.
configure enhanced-dos-protect rate-limit
unconfigure enhanced-dos-protect
861

Advertisement

Table of Contents
loading

This manual is also suitable for:

Extremeware 7.5

Table of Contents