Cisco WS-C6506 Software Manual page 433

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Chapter 15
Configuring Access Control
Clearing the ARP Traffic-Inspection Statistics
To clear the ARP traffic-inspection statistics, perform this task in privileged mode:
Task
Clear the ARP traffic-inspection statistics.
Without the optional argument, entering the command clears the ARP traffic-inspection global statistics
counters and the ARP traffic-inspection statistics counters for all the ACLs. If you supply the optional
acl_name argument, only the ARP traffic-inspection statistics for that particular ACL are cleared.
You can enter the clear security acl commands to clear the ARP traffic-inspection configuration
Note
settings.
Configuring Rate Limiting on a Global Basis
You can rate limit the number of ARP traffic-inspection packets that are sent to the supervisor engine
CPU globally. By default, the ARP traffic-inspection traffic is rate limited to 500 packets per second.
The minimum value is 500, and the maximum value is 2000 packets per second. For Supervisor
Engine 720, the minimum value that is enforced by the hardware is 10 packets per second (values
between 1– 9 are set to 10). To disable rate limiting, set the value to 0.
Note
Rate limiting might be shared by multiple features. To display the features that share rate limiting, enter
the show security acl feature ratelimit command.
To rate limit the number of ARP traffic-inspection packets that are sent to the CPU on a global basis,
perform this task in privileged mode:
Task
Step 1
Rate limit the number of ARP traffic-inspection
packets that are sent to the supervisor engine CPU on
a global basis.
Step 2
Display the global rate-limit value.
Step 3
Display all the rate-limiter settings that are configured
on the switch processor and the route processor.
This example shows how to rate limit the number of ARP traffic-inspection packets that are sent to the
CPU to 1000:
Console> (enable) set security acl feature ratelimit 1000
Dot1x DHCP and ARP Inspection global rate limit set to 1000 pps.
Console> (enable)
Console> (enable) show security acl feature ratelimit
Rate limit value in packets per second = 1000
Protocols set for rate limiting = Dot1x DHCP, ARP Inspection
Console> (enable)
OL-8978-04
Command
clear security acl arp-inspection statistics
[acl_name]
Command
set security acl feature ratelimit rate
show security acl feature ratelimit
show rate-limit
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
Using VACLs in Your Network
15-37

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents