Cisco Systems 7600 SERIES manual Configuring Unicast Flood Protection, 23-21

Page 21

Chapter 23 Configuring Network Security

Configuring Unicast Flood Protection

This example shows how to enable Unicast RPF exist-only checking mode on Gigabit Ethernet port 4/1:

Router(config)# interface gigabitethernet 4/1

Router(config-if)#ip verify unicast source reachable-via any

Router(config-if)# end

Router#

This example shows how to enable Unicast RPF strict checking mode on Gigabit Ethernet port 4/2:

Router(config)# interface gigabitethernet 4/2

Router(config-if)#ip verify unicast source reachable-via rx

Router(config-if)# end

Router#

This example shows how to verify the configuration:

Router# show running-config interface gigabitethernet 4/2

Building configuration...

Current configuration : 114 bytes

!

interface GigabitEthernet4/2 ip address 42.0.0.1 255.0.0.0 ip verify unicast reverse-path no cdp enable

end

Router# show running-config interface gigabitethernet 4/1

Building configuration...

Current configuration : 114 bytes

!

interface GigabitEthernet4/1 ip address 41.0.0.1 255.0.0.0

ip verify unicast reverse-path (RPF mode on g4/1 also changed to strict-check RPF mode) no cdp enable

end Router#

Configuring Unicast Flood Protection

The unicast flood protection feature protects the system from disruptions caused by unicast flooding. The Cisco 7600 series routers use forwarding tables to direct traffic to specific ports based on the VLAN number and the destination MAC address of the frame. When there is no entry corresponding to the frame’s destination MAC address in the incoming VLAN, the frame is sent to all forwarding ports within the respective VLAN, which causes flooding. Limited flooding is part of the normal switching process, but continuous flooding can cause adverse performance effects on the network.

When you enable the unicast flood protection feature, the system sends an alert when the rate limit has been exceeded, filters the traffic, or shuts down the port generating the floods when it detects unknown unicast floods exceeding a threshold.

To configure unicast flood protection, perform this task:

 

Command

Purpose

Step 1

 

 

Router(config)# [no] mac-address-table

Enables unicast flood protection globally.

 

unicast-flood {limit kfps} {vlan vlan} {filter

 

 

timeout alert shutdown}

 

Step 2

 

 

Router# show mac-address-table unicast-flood

Displays unicast flood protection information.

 

 

 

 

 

Cisco 7600 Series Router Cisco IOS Software Configuration Guide—12.1E

 

 

 

 

 

 

78-14064-04

 

 

23-21

 

 

 

 

 

Image 21
Contents ACL Configuration Guidelines This chapter consists of these sections23-1 23-2 Hardware and Software ACL Support23-3 Determining Layer 4 Operation UsageDetermining Logical Operation Unit Usage Configuring the Cisco IOS Firewall Feature SetMore detailed example follows 23-423-5 Cisco IOS Firewall Feature Set Support OverviewConfiguring Cbac on Cisco 7600 Series Routers Firewall Configuration Guidelines and RestrictionsRestrictions Guidelines23-7 Configuring MAC Address-Based Traffic BlockingUnderstanding VACLs Configuring Vlan ACLsVacl Overview 23-8Bridged Packets VACLs and Cbac cannot be configured on the same interfaceSame interface Igmp packets are not checked against VACLs23-10 Routed PacketsThese sections describe configuring VACLs Configuring VACLsMulticast Packets 23-11Defining a Vlan Access Map Vacl Configuration OverviewTo define a Vlan access map, perform this task 23-12Configures the match clause in a Vlan access map sequence Configuring a Match Clause in a Vlan Access Map SequenceDeletes the match clause in a Vlan access map sequence 23-13Configuring an Action Clause in a Vlan Access Map Sequence Applying a Vlan Access Map23-14 Verifying Vlan Access Map Configuration Vlan Access Map Configuration and Verification Examples23-15 23-16 Configuring a Capture Port23-17 Configuring Vacl Logging23-18 Configuring TCP InterceptConfiguring Unicast RPF Configuring Unicast Reverse Path ForwardingUnderstanding Unicast RPF Support Enabling Self-Pinging23-20 Configuring the Unicast RPF Checking ModeConfiguring Unicast Flood Protection This example shows how to verify the configuration23-21 23-22 Configuring MAC Move Notification23-23 23-24
Related manuals
Manual 74 pages 38.06 Kb