Default System Rate Limiting of Inbound CPU Traffic

Default CPU rate limiting is a CPU protection scheme that limits certain traffic types.

Unnecessary traffic to the switch CPU lowers the efficiency of the CPU and delays handling of other traffic that requires processing. Default CPU rate limiting identifies the traffic type and assigns a maximum rate limit to the traffic type. The traffic types that are subjected to rate limiting include broadcast ARP and other exceptions, such as TTL exceed, IP MTU failed, reverse path check failed, IP fragments, and unsupported tunneling. Each of these types is rate limited individually.

The following table shows the rate limits for each rate-limited packet type. You cannot configure these rates.

All currently supported FastIron devices support the default CPU rate limiting feature.

Note: It is possible to configure fixed rate limiting for inbound CPU traffic. Refer to Applying ACLs to rate limit inbound CPU traffic for more information.

Default CPU Rate Limits for Packet Type

Packet Type Rate Limit in Packets per Second
ARP 6000
IP TTL exceed 150
Reverse path check failed
IP MTU failed 3000
IP tunnel-terminated packets that are fragmented or have options
IP tunnel-terminated packets with unsupported GRE tunnel header
IP Unicast packets mirrored to CPU due to ICMP redirect 100
Bridge packets forwarded to CPU 5000