Configuring Rate Limit For Icmp Error Messages; Specifying The Source Address For Icmp Packets - H3C MSR 2600 Configuration Manual

Layer 3
Hide thumbs Also See for MSR 2600:
Table of Contents

Advertisement

Sending ICMP error packets facilitates network management, but sending excessive ICMP packets
increases network traffic. A device's performance degrades if it receives a lot of malicious ICMP packets
that cause it to respond with ICMP error packets.
To prevent such problems, you can disable the device from sending ICMP error packets. A device
disabled from sending ICMP time-exceeded packets does not send ICMP TTL Expired packets but can still
send ICMP Fragment Reassembly Timeout packets.

Configuring rate limit for ICMP error messages

To avoid sending excessive ICMP error messages within a short period that might cause network
congestion, you can limit the rate at which ICMP error messages are sent. A token bucket algorithm is
used with one token representing one ICMP error message. Tokens are placed in the bucket at a specific
interval until the maximum number of tokens that the bucket can hold is reached. Tokens are removed
from the bucket when ICMP error messages are sent. When the bucket is empty, ICMP error messages
are not sent until a new token is placed in the bucket.
To configure rate limit for ICMP error messages:
Step
1.
Enter system view.
2.
Set the interval and bucket
size for ICMP error
messages

Specifying the source address for ICMP packets

Perform this task to specify the source IP address for outgoing ping echo request and ICMP error
messages. It is a good practice to specify the IP address of the loopback interface as the source IP
address. This feature helps users to locate the sending device easily.
If you specify an IP address in the ping command, ping echo requests use the specified address as the
source IP address rather than the IP address specified by the ip icmp source command.
To specify the source IP address for ICMP packets:
Step
1.
Enter system view.
2.
Specify the source address
for outgoing ICMP
packets.
Command
system-view
ip icmp error-interval
milliseconds [ bucketsize ]
Command
system-view
ip icmp source [ vpn-instance
vpn-instance-name ] ip-address
167
Remarks
N/A
By default, the bucket allows a maximum
of 10 tokens, and tokens are placed in
the bucket at the interval of 100
milliseconds.
To disable the ICMP rate limit, set the
interval to 0 milliseconds.
Remarks
N/A
By default, the device uses the IP address
of the sending interface as the source IP
address for outgoing ICMP packets.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents