Control Plane Policy
1) control-plane host
a) service-policy input
b) service-policy type queue-threshold input
only for some protocols:
c) service-policy type port-filter input
2) control-plane cef-exception
For non-IP traffic:
3) control-plane transit
For packets/traffic which transit the device:
1) control-plane host
a) service-policy input
!
class-map match-all UDP-FLOOD
match access-group 101
!
policy-map UDP-FLOOD-PM
class UDP-FLOOD
police rate 16000 bps
conform-action drop
!
control-plane
service-policy input UDP-FLOOD-PM
!
b) service-policy type queue-threshold input
only for some protocols:
R2(config-cmap)#match protocol ?
bgp Border Gateway Protocol
dns Domain Name Server lookup
ftp File Transfer Protocol
http World Wide Web traffic
igmp Internet Group Management Protocol
snmp Simple Network Management Protocol
ssh Secure Shell Protocol
syslog Syslog Server
telnet Telnet
tftp Trivial File Transfer Protocol
R2(config-cmap)#
class type queue-threshold HTTP-CM
match protocol http
!
policy-map type queue-threshold HTTP-PM
class HTTP-CM
queue-limit 10
c) service-policy type port-filter input
class-map type port-filter TASK1-1-closed-ports
match closed-ports
!
policy-map type port-filter TASK1-1-closed-ports-PM
class TASK1-1-closed-ports
drop
!
control-plane host
service-policy type port-filter input TASK1-1-closed-ports-PM
!
R2#sh control-plane host open-ports
Active internet connections (servers and established)
Prot Local Address Foreign Address Service State
tcp *:23 *:0 Telnet LISTEN
tcp *:179 *:0 BGP LISTEN
R2#
2) control-plane cef-exception
For non-IP traffic:
policy-map TASK1-2-block-non-IP
class class-default
police rate 100 pps
!
control-plane cef-exception
service-policy input TASK1-2-block-non-IP
!
3) control-plane transit
For packets/traffic which transit the device:
class-map match-all TASK1-4-frag
match access-group 103
!
policy-map TASK1-4-frag-PM
class TASK1-4-frag
police rate 1000000 pps
!
control-plane transit
service-policy input TASK1-4-frag-PM
Comments
Post a Comment