Forwarding Information Base Rate-Limiting; Apr Throttling - Cisco 7609 Configuration Manual

Cisco ios software configuration guide—12.1e
Hide thumbs Also See for 7609:
Table of Contents

Advertisement

Chapter 24
Configuring Denial of Service Protection

Forwarding Information Base Rate-Limiting

The forwarding information base (FIB) rate-limiting allows all packets that require software processing
to be rate limited.
The following FIB rate-limiting usage guidelines apply:
The following example shows traffic destined for a nonexistent host address on a locally connected
subnet. Normally, the ARP request would result in an ARP reply and the installation of a FIB adjacency
for this traffic. However, the adjacency in the FIB for the destination subnet would continue to receive
traffic that would, in turn, be forwarded for software processing. By applying rate-limiting to this traffic,
the rate of traffic forwarded for software processing can be limited to a manageable amount.
Router# show ip eigrp neighbors
IP-EIGRP neighbors for process 200
H
0
Router# show ip ospf neighbors
Neighbor ID
6.6.6.122
Router#
Router# show arp | include 199.2.250.250
Internet
Router#
1w6d: %OSPF-5-ADJCHG: Process 100, Nbr 6.6.6.122 on Vlan46 from FULL to DOWN, Neighbor
Down: Dead timer expired
Router# show ip eigrp neighbors
IP-EIGRP neighbors for process 200
Router#
Router# configure terminal
Enter configuration commands, one per line.
Router(config)# mls ip cef rate-limit 1000
Router(config)# end
Router#
1w6d: %SYS-5-CONFIG_I: Configured from console by console
Router#
1w6d: %OSPF-5-ADJCHG: Process 100, Nbr 6.6.6.122 on Vlan46 from LOADING to FULL, Loading
Done
Router# show ip eigrp neighbors
IP-EIGRP neighbors for process 200
H
0
Router#

APR Throttling

ARP throttling limits the rate at which packets destined to a connected network are forwarded to the
route processor. Most of these packets are dropped, but a small number are sent to the router (rate
limited).
78-14064-04
FIB rate-limiting does not limit the rate of multicast traffic.
FIB rate-limiting does not differentiate between legitimate and illegitimate traffic (for example,
tunnels, Telnet).
FIB rate-limiting applies aggregate rate-limiting and not per flow rate-limiting.
Address
4.4.4.122
Pri
State
1
FULL/BDR
199.2.250.250
Address
4.4.4.122
Interface
Hold Uptime
(sec)
Vl44
11 00:00:26
Dead Time
Address
00:00:36
6.6.6.122
0
Incomplete
End with CNTL/Z.
Interface
Hold Uptime
(sec)
Vl44
12 00:00:07
Cisco 7600 Series Router Cisco IOS Software Configuration Guide—12.1E
Configuring DoS Protection
SRTT
RTO
Q
Seq Type
(ms)
Cnt Num
8
200
0
6534
Interface
Vlan46
attack starts
ARPA
traffic rate limited to 1000 pps
SRTT
RTO
Q
Seq Type
(ms)
Cnt Num
12
200
0
6536
24-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents