Alcatel-Lucent 7450 System Management Manual page 41

Ethernet service switch
Hide thumbs Also See for 7450:
Table of Contents

Advertisement

is not configured, eth-cfm entries in the policy will be ignored. It is also possible to apply a
policy to a SAP/Binding configuring "eth-cfm-monitoring" which does not have an MP. In
this case, although these entries are enforced, no packets are being redirect to the CPU due to
the lack of an MP.
By default, rates are applied on a per peer basis. This means each individual peer is subject to
the rate. However, it is suggested that the "aggregate" option be configured to apply the rate to
the sum total of all peers. MIPs for example only respond to Loopback Messages and
Linktrace Messages. These are typically on demand functions and per peer rate limiting is
likely not required thus making the aggregate function a more appealing model.
"eth-cfm-monitoring" and "mac-monitoring" are mutually exclusive and cannot be configured
on the same SAP/Binding "mac-monitoring" is used in combination with the traditional CPU
protection and is not specific to the eth-cfm rate limiting feature describe here.
When an MP is configured on a SAP/Binding within a service which allows an external
source to communicate with that MP, for example a User to Network Interface (UNI), it is
suggested that "eth-cfm-monitoring" with the "aggregate" option be configured on all SAP/
Bindings to provide the highest level of rate control.
The example below shows a sample configuration for a policy and the application of that
policy to a SAP in a VPLS service configured with a MP.
Policy 1 entry 10 limits all eth-cfm traffic redirected to the CPU for all possible combinations
to 1 packet per second. Policy 1 entry 20 limits all possible combinations to a rate of zero,
dropping all request which match any combination. If entry 20 did not exist then only rate
limiting of the entry 10 matches would occur and any other eth-cfm packets redirected to the
CPU would not be bound by a CPU protection rate.
config>sys>security>cpu-protection#
policy 1
config>service>vpls#
sap 1/1/4:100
IOM1s are restricted to Down MEPs and ingress MIP for this feature. This feature is not
supported on UP MEPs and egress MIPs for this IOM type.
7450 ESS System Mangement Guide
eth-cfm
entry 10 level 5-7 opcode 3,5 rate 1
entry 20 level 0-7 opcode 0-255 rate 0
cpu-protection 1 eth-cfm-monitoring aggregate
eth-cfm
mip
no shutdown
Security
Page 41

Advertisement

Table of Contents
loading

Table of Contents