BUM Suppression Port Dampening

The BUM suppression port dampening allows you to monitor BUM traffic drops in a port for a configured time span. Rate limiting of BUM traffic is used to protect a switch, router node, or network from Denial of Service (DoS) attacks or unintentional excess traffic conditions. If the ingress BUM traffic exceeds the configured rate limit value, the excess traffic is dropped. If the traffic drop count exceeds a set number within a set time interval, the port is shut down (dampened) for a user-configured period.

Enabling BUM Suppression Port Dampening

Note: You can set the rate limit interval in either kilobits per second (kbps) or packets per second (pps).
Note: Set the log timer interval when kbps rate limit is configured (broadcast, unknown-unicast, and multicast).

Complete the following steps to enable BUM suppression port dampening in kbps.

  1. Enter global configuration mode.
    device# configure terminal
  2. Set the rate limit log interval.
    device(config)# rate-limit-log 3

    In this example, the kbps rate interval is set to 3 minutes. The value can be from 1 through 10 minutes. The default value is 5 minutes.

    At every rate-limit-log interval, the device checks whether the threshold configured is exceeded or not to take the port-shutdown action.

  3. Enter interface configuration mode.
    device(config)# interface ethernet 1/1/1
  4. Enable broadcast suppression port dampening in kbps with a shutdown interval.
    device(config-if-e10000-1/1/1)# broadcast limit 100 kbps threshold 2000 action port-shutdown 7
  5. Enable multicast suppression port dampening in kbps with a shutdown interval.
    device(config-if-e10000-1/1/1)# multicast limit 100 kbps threshold 2000 action port-shutdown 7
  6. Enable unknown unicast suppression port dampening in kbps.
    device(config-if-e10000-1/1/1)# unknown-unicast limit 100 kbps threshold 2000 action port-shutdown

    Because no value is indicated for the port-shutdown parameter, the default of 5 minutes is applied.

  7. Verify the configuration.
    device# show running-config interface ethernet 1/1/1 | i limit
    broadcast limit 100 kbps threshold 2000 action port-shutdown 7
    multicast limit 100 kbps threshold 2000 action port-shutdown 
    unknown-unicast limit 100 kbps threshold 2000 action port-shutdown

Complete the following steps to enable BUM suppression port dampening in pps.

  1. Enter global configuration mode.
    device# configure terminal
  2. Set the rate limit log interval.
    device(config)# rate-limit-pps-log 200

    In this example, the pps rate interval is set to 200 seconds. The value can be from 1 through 600 seconds. The default value is 300 seconds.

    At every rate-limit-log-pps interval, the device checks whether the threshold configured is exceeded or not to take the port-shutdown action.

  3. Enter interface configuration mode.
    device(config)# interface ethernet 1/1/2
  4. Enable broadcast suppression port dampening in pps with a shutdown interval.
    device(config-if-e10000-1/1/2)# broadcast limit 1500 pps threshold 2000 action port-shutdown 7
  5. Enable multicast suppression port dampening in pps with a shutdown interval.
    device(config-if-e10000-1/1/2)# multicast limit 100 pps threshold 2000 action port-shutdown 7
  6. Enable unknown unicast suppression port dampening in pps.
    device(config-if-e10000-1/1/2)# unknown-unicast limit 1500 pps threshold 2000 action port-shutdown

    Because no value is indicated for the port-shutdown parameter, the default of 300 seconds is applied.

  7. Verify the configuration.
    device# show running-config interface ethernet 1/1/2 | i limit
    broadcast limit 1500 pps threshold 2000 action port-shutdown 7
    multicast limit 100 pps threshold 2000 action port-shutdown 7
    unknown-unicast limit 1500 pps threshold 2000 action port-shutdown
BUM Suppression Port Dampening Configuration Example
device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e40000-1/1/1)# broadcast limit 100 kbps threshold 2000 action port-shutdown 7
device(config-if-e40000-1/1/1)# unknown-unicast limit 100 kbps threshold 2000 action port-shutdown 7
device(config-if-e40000-1/1/1)# multicast limit 100 kbps threshold 2000 action port-shutdown 7
device# configure terminal
device(config)# interface ethernet 1/1/2
device(config-if-e40000-1/1/2)# broadcast limit 100 pps threshold 2000 action port-shutdown 7
device(config-if-e40000-1/1/2)# unknown-unicast limit 100 pps threshold 2000 action port-shutdown 7
device(config-if-e40000-1/1/2)# multicast limit 100 pps threshold 2000 action port-shutdown 7