Configuring UDP Rate Limit

On ICX 8200 switches, the following commands can be entered in global configuration mode to enable rate limiting for all UDP packets destined to the CPU.
  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Enter the ddos-guard udp enable port all command to enable DDoS protection, on all ports, against the UDP packets.
    device(config)# ddos-guard udp enable port all
  3. (Optional) Enter the ddos-guard udp enable port command to enable DDoS protection, on a specific range of ports, against the UDP packets coming to the CPU. Specify the start and end ports for which you want to enable UDP filtering. The port range is from 0 to 65535.
    device(config)# ddos-guard udp enable port 1000 to 30000
  4. Enter the ip udp burst-max command to enable UDP rate limit on data ports and specify the the maximum allowable burst rate (packets per second). If the number of UDP packets exceeds the maximum burst value, excess packets are dropped, and traffic flows at the configured burst max value. The burst-max value parameter can be from 125 to 1,00,000 Kbps. The following example limits the rate of UDP data packets to 2000 packets per second.
    device(config)# ip udp burst-max 2000
In the above example, if incoming UDP traffic exceeds 2000 packets per second, all UDP packet traffic on the configured ports is limited to 125 packets per second and the excess packets are dropped.