Configuring UDP Rate Limit
On ICX 8200 switches, the following
commands can be entered in global configuration mode to enable rate limiting for all
UDP
packets destined to the CPU.
- Enter the
configure terminalcommand to enter global configuration mode. - Enter the
ddos-guard udp enable port allcommand to enable DDoS protection, on all ports, against the UDP packets. - (Optional) Enter the
ddos-guard udp enable portcommand to enable DDoS protection, on a specific range of ports, against the UDP packets coming to the CPU. Specify the start and end ports for which you want to enable UDP filtering. The port range is from 0 to 65535. - Enter the
ip udp burst-maxcommand to enable UDP rate limit on data ports and specify the the maximum allowable burst rate (packets per second). If the number of UDP packets exceeds the maximum burst value, excess packets are dropped, and traffic flows at the configured burst max value. The burst-max value parameter can be from 125 to 1,00,000 Kbps. The following example limits the rate of UDP data packets to 2000 packets per second.