Dell S5148F-ON OS10 Enterprise Edition User Guide Release 10.3.2E-R1 - Page 451

Control-plane policing, Con control-plane policing

Page 451 highlights

• cir committed-rate-Enter a committed rate value in kilobits per second (kbps) (0 to 40000000). • bc committed-burst-size-(Optional) Enter a committed burst size in packets for control plane and kbps (16 to 200000, default 200). • pir peak-rate-Enter a peak-rate value in kbps (0 to 40000000). • be peak-burst-size-(Optional) Enter a peak burst size in kbps (16 to 200000, default 200). 4 (Optional) Configure traffic policing for a specific queue in POLICY-MAP-CLASS-MAP mode. Queue number range is from 0 to 7 for qos policy map and 0 to 11 for control-plane policy map. set qos-group queue-number Configure policy-based rate policy OS10(config)# policy-map type qos galaxy OS10(conf-pmap-qos)# class bigbang OS10(conf-pmap-c-qos)# police cir 5 bc 30 pir 20 be 40 Configure rate policing on specific queue OS10(config)# policy-map bronze OS10(conf-pmap-qos)# class silver OS10(conf-pmap-c-qos)# set qos-group 7 OS10(conf-pmap-c-qos)# police cir 5 pir 30 View policy-map OS10(conf-pmap-c-qos)# do show policy-map Service-policy (qos) input: galaxy Class-map (qos): bigbang police cir 5 bc 30 pir 20 be 40 Service-policy (qos) input: bronze Class-map (qos): silver police cir 5 bc 100 pir 30 be 100 Control-plane policing Control-plane policing (CoPP) increases security on the system by protecting the route processor from unnecessary traffic and giving priority to important control plane and management traffic. CoPP uses a dedicated control plane configuration through the QoS CLIs to provide filtering and rate-limiting capabilities for the control plane packets. If the rate of control packets towards the CPU is higher than it can handle, CoPP provides a method to selectively drops some of the control traffic so the CPU can process high-priority control traffic. You can use CoPP to rate-limit traffic through each CPU port queue of the NPU. CoPP applies policy actions on all control-plane traffic. The control-plane class map does not use any match criteria. To enforce rate-limiting or rate policing on control-plane traffic, create policy maps. You can use the control-plane command to attach the CoPP service policies directly to the control-plane. The default rate limits apply to 12 CPU queues and the protocols mapped to each CPU queue. The control packet type to CPU ports control queue assignment is fixed. The only way you can limit the traffic towards the CPU is choose a low priority queue, and apply ratelimits on that queue to find a high rate of control traffic flowing through that queue. See show control-plane info for specific information on protocols and rate limits of CPU queues. Configure control-plane policing Rate-limiting the protocol CPU queues requires configuring control-plane type QoS policies. • Create QoS policies (class maps and policy maps) for the desired CPU-bound queue. Quality of service 451

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550

cir
committed-rate
—Enter a committed rate value in kilobits per second (kbps) (0 to 40000000).
bc
committed-burst-size
—(Optional) Enter a committed burst size in packets for control plane and kbps (16 to 200000,
default 200).
pir
peak-rate
—Enter a peak-rate value in kbps (0 to 40000000).
be
peak-burst-size
—(Optional) Enter a peak burst size in kbps (16 to 200000, default 200).
4
(Optional)
Configure
traffic
policing for a
specific
queue in POLICY-MAP-CLASS-MAP mode. Queue number range is from 0 to 7 for
qos policy map and 0 to 11 for control-plane policy map.
set qos-group
queue-number
Configure
policy-based rate policy
OS10(config)# policy-map type qos galaxy
OS10(conf-pmap-qos)# class bigbang
OS10(conf-pmap-c-qos)# police cir 5 bc 30 pir 20 be 40
Configure
rate policing on
specific
queue
OS10(config)# policy-map bronze
OS10(conf-pmap-qos)# class silver
OS10(conf-pmap-c-qos)# set qos-group 7
OS10(conf-pmap-c-qos)# police cir 5 pir 30
View policy-map
OS10(conf-pmap-c-qos)# do show policy-map
Service-policy (qos) input: galaxy
Class-map (qos): bigbang
police cir 5 bc 30 pir 20 be 40
Service-policy (qos) input: bronze
Class-map (qos): silver
police cir 5 bc 100 pir 30 be 100
Control-plane policing
Control-plane policing (CoPP) increases security on the system by protecting the route processor from unnecessary
traffic
and giving
priority to important control plane and management
traffic.
CoPP uses a dedicated control plane
configuration
through the QoS CLIs to
provide
filtering
and rate-limiting capabilities for the control plane packets.
If the rate of control packets towards the CPU is higher than it can handle, CoPP provides a method to selectively drops some of the
control
traffic
so the CPU can process high-priority control
traffic.
You can use CoPP to rate-limit
traffic
through each CPU port queue of
the NPU.
CoPP applies policy actions on all control-plane
traffic.
The control-plane class map does not use any match criteria. To enforce rate-limiting
or rate policing on control-plane
traffic,
create policy maps. You can use the
control-plane
command to attach the CoPP service
policies directly to the control-plane.
The default rate limits apply to 12 CPU queues and the protocols mapped to each CPU queue. The control packet type to CPU ports
control queue assignment is
fixed.
The only way you can limit the
traffic
towards the CPU is choose a low priority queue, and apply rate-
limits on that queue to
find
a high rate of control
traffic
flowing
through that queue.
See
show control-plane info
for
specific
information on protocols and rate limits of CPU queues.
Configure
control-plane policing
Rate-limiting the protocol CPU queues requires
configuring
control-plane type QoS policies.
Create QoS policies (class maps and policy maps) for the desired CPU-bound queue.
Quality of service
451