Configuring ICMP Threshold Values on an Interface

Follow these steps to configure ICMP threshold values.

  1. Enter global configuration mode.
    device# configure terminal
  2. Specify the interface to be configured to enter interface configuration sub-mode.
    device(config)# interface ethernet 1/3/11
  3. Specify in Kbps the burst-normal and burst-max threshold values for ICMP packets. On the same line, specify the lockup period in seconds.
    device(config-if-e1000-1/3/11)# ip icmp attack-rate burst-normal 2000 burst-max 2500 lockup 300

For Layer 3 router code, if the interface is part of a VLAN that has a router VE, you must configure ICMP attack protection at the VLAN level. Otherwise, you can configure this feature at the interface level as shown previously. When ICMP attack protection is configured at the VLAN level, it applies to routed traffic only. It does not affect switched traffic.

You must configure VLAN information for the port before configuring ICMP attack protection. You cannot change the VLAN configuration for a port on which ICMP attack protection is enabled.

To set threshold values for ICMP packets received on VLAN 2, enter the following commands.

device# configure terminal
device(config)# vlan 2
device(config-vlan-2)# ip icmp attack-rate burst-normal 5000 burst-max 10000 lockup 300