DDOS Limitations

Keep the following items in mind when configuring DDOS protection:

  • In a Campus Fabric (SPX) environment, ICMP and TCP SYN attack protection cannot be configured directly on PE interfaces. You must add the PE interface to a VLAN and configure protection at the VLAN level.
  • In a Campus Fabric (SPX) environment, when protection against both local and transit DOS attacks are configured on a PE VLAN, the ICX device creates blockers for both local and transit traffic on receiving local traffic beyond threshold values.