BUM Suppression Port Dampening
The BUM suppression port dampening allows you to monitor BUM traffic drops in a port for a configured time span. Rate limiting of BUM traffic is used to protect a switch, router node, or network from Denial of Service (DoS) attacks or unintentional excess traffic conditions. If the ingress BUM traffic exceeds the configured rate limit value, the excess traffic is dropped. If the traffic drop count exceeds a set number within a set time interval, the port is shut down (dampened) for a user-configured period.
Enabling BUM Suppression Port Dampening
Complete the following steps to enable BUM suppression port dampening in kbps.
- Enter global configuration
mode.
device# configure terminal
- Set the rate limit log
interval.
device(config)# rate-limit-log 3
In this example, the kbps rate interval is set to 3 minutes. The value can be from 1 through 10 minutes. The default value is 5 minutes.
At every rate-limit-log interval, the device checks whether the threshold configured is exceeded or not to take the port-shutdown action.
- Enter interface configuration
mode.
device(config)# interface ethernet 1/1/1
- Enable broadcast suppression port
dampening in kbps with a shutdown
interval.
device(config-if-e10000-1/1/1)# broadcast limit 100 kbps threshold 2000 action port-shutdown 7
- Enable multicast suppression port
dampening in kbps with a shutdown
interval.
device(config-if-e10000-1/1/1)# multicast limit 100 kbps threshold 2000 action port-shutdown 7
- Enable unknown unicast
suppression port dampening in
kbps.
device(config-if-e10000-1/1/1)# unknown-unicast limit 100 kbps threshold 2000 action port-shutdown
Because no value is indicated for the port-shutdown parameter, the default of 5 minutes is applied.
- Verify the
configuration.
device# show running-config interface ethernet 1/1/1 | i limit broadcast limit 100 kbps threshold 2000 action port-shutdown 7 multicast limit 100 kbps threshold 2000 action port-shutdown unknown-unicast limit 100 kbps threshold 2000 action port-shutdown
Complete the following steps to enable BUM suppression port dampening in pps.
- Enter global configuration
mode.
device# configure terminal
- Set the rate limit log
interval.
device(config)# rate-limit-pps-log 200
In this example, the pps rate interval is set to 200 seconds. The value can be from 1 through 600 seconds. The default value is 300 seconds.
At every rate-limit-log-pps interval, the device checks whether the threshold configured is exceeded or not to take the port-shutdown action.
- Enter interface configuration
mode.
device(config)# interface ethernet 1/1/2
- Enable broadcast suppression port
dampening in pps with a shutdown
interval.
device(config-if-e10000-1/1/2)# broadcast limit 1500 pps threshold 2000 action port-shutdown 7
- Enable multicast suppression port
dampening in pps with a shutdown
interval.
device(config-if-e10000-1/1/2)# multicast limit 100 pps threshold 2000 action port-shutdown 7
- Enable unknown unicast
suppression port dampening in
pps.
device(config-if-e10000-1/1/2)# unknown-unicast limit 1500 pps threshold 2000 action port-shutdown
Because no value is indicated for the port-shutdown parameter, the default of 300 seconds is applied.
- Verify the
configuration.
device# show running-config interface ethernet 1/1/2 | i limit broadcast limit 1500 pps threshold 2000 action port-shutdown 7 multicast limit 100 pps threshold 2000 action port-shutdown 7 unknown-unicast limit 1500 pps threshold 2000 action port-shutdown
device# configure terminal device(config)# interface ethernet 1/1/1 device(config-if-e40000-1/1/1)# broadcast limit 100 kbps threshold 2000 action port-shutdown 7 device(config-if-e40000-1/1/1)# unknown-unicast limit 100 kbps threshold 2000 action port-shutdown 7 device(config-if-e40000-1/1/1)# multicast limit 100 kbps threshold 2000 action port-shutdown 7
device# configure terminal device(config)# interface ethernet 1/1/2 device(config-if-e40000-1/1/2)# broadcast limit 100 pps threshold 2000 action port-shutdown 7 device(config-if-e40000-1/1/2)# unknown-unicast limit 100 pps threshold 2000 action port-shutdown 7 device(config-if-e40000-1/1/2)# multicast limit 100 pps threshold 2000 action port-shutdown 7