Cisco ME 3400 Software Configuration Manual page 621

Ethernet access switch
Hide thumbs Also See for ME 3400:
Table of Contents

Advertisement

Chapter 32
Configuring Control-Plane Security
Table 32-1
Control-Plane Security Actions on Layer 2 Protocol Packets Received on a UNI or ENI
Protocol
STP
RSVD_STP (reserved IEEE
802.1D addresses)
PVST+
LACP
PAgP
IEEE 802.1x
CDP
LLDP
DTP
UDLD
VTP
CISCO_L2 (any other Cisco
Layer 2 protocols with the MAC
address 01:00:0c:cc:cc:cc)
KEEPALIVE (MAC address,
SNAP encapsulation, LLC, Org
ID, or HDLC packets)
Ethernet Connectivity Fault
Management (CFM)
1. Layer 2 protocol traffic is rate-limited when Layer 2 protocol tunneling is enabled for any protocol on any port.
The switch automatically allocates 27 control-plane security policers for CPU protection. At system
bootup, it assigns a policer to each port numbered 0 to 26. The policer assigned to a port determines if
the protocol packets arriving on the port are rate-limited or dropped. A policer of 26 means a drop policer
and is a global policer; any traffic type shown as 26 on any port is dropped. A policer of a value of 0 to
OL-9639-07
Default
When Feature Is Enabled
Dropped
Rate limited
STP can be enabled only on ENIs.
Note
Dropped
When the Ethernet Link Management Interface
(ELMI) is enabled, globally or on a per-port basis
whichever is configured last, a throttle policer is
assigned to a port. When ELMI is disabled (globally or
on a port, whichever is configured last), a drop policer
is assigned to a port.
Dropped
Dropped
Rate limited
LACP can be enabled only on ENIs.
Note
Dropped
Rate limited
PAgP can be enabled only on ENIs.
Note
Dropped
Rate limited
Dropped
Rate limited
CDP can be enabled only on ENIs.
Note
Dropped
Rate limited
LLDP can be enabled only on ENIs.
Note
Dropped
Dropped
Rate limited
Dropped
Dropped
Rate-limited –
No policer
When CFM is enabled globally, a throttle policer is
assigned
assigned to all ports. When CFM is disabled globally,
a NULL policer is assigned to all ports.
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
Understanding Control-Plane Security
When Layer 2
Protocol Tunneling
1
Is Enabled
Rate-limited
Rate limited
Rate limited
Rate limited
Rate limited
Rate limited
Rate limited
Rate limited
Rate limited if
CDP, DTP, UDLD,
PAGP, or VTP are
Layer 2 tunneled
32-3

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents