The linkup-car command sets the CPCAR value for packets of a protocol connection, including the Committed Information Rate (CIR) and Committed Burst Size (CBS).
The undo linkup-car command restores the default CPCAR rate limit.
Table 1 lists the default CIR and CBS values for the setup of BGP, BGP4+, FTP, IPv6 FTP, HTTP, HTTPS, IKE, IPSEC-ESP, ISIS, OSPF, OSPFv3, SSH, TELNET, and TFTP connections; the CIR and CBS for sending packets of IP-CLOUD connections are 2048 kbit/s and 385024 bytes respectively.
linkup-car packet-type { bgp | bgp4plus | ftp | ftpv6 | http | https | ike | ip-cloud | ipsec-esp | isis | ospf | ospfv3 | ssh | telnet | tftp } cir cir-value [ cbs cbs-value ]
undo linkup-car packet-type { bgp | bgp4plus | ftp | ftpv6 | http | https | ike | ip-cloud | ipsec-esp | isis | ospf | ospfv3 | ssh | telnet | tftp }
Parameter |
Description |
Value |
---|---|---|
bgp |
Indicates that the protocol type is BGP. |
- |
bgp4plus |
Indicates that the protocol type is BGP4+. |
- |
ftp |
Indicates that the protocol type is FTP. |
- |
ftpv6 |
Indicates that the protocol type is IPv6 FTP. |
- |
http |
Indicates that the protocol type is HTTP. |
- |
https |
Indicates that the protocol type is HTTPS. |
- |
ike |
Indicates that the protocol type is IKE. This parameter does not take effect in non-NAT scenarios. |
- |
ip-cloud |
Indicates that the protocol type is IP-CLOUD. |
- |
ipsec-esp |
Indicates that the protocol type is IPSEC-ESP. ipsec-esp specified in the linkup-car command indicates the type of the protocol used by IPsec EVPN, and ipsec-esp specified in the car command indicates the type of the protocol used by OSPFv3. |
- |
isis |
Indicates that the protocol type is ISIS. |
- |
ospf |
Indicates the protocol type is OSPF. |
- |
ospfv3 |
Indicates the protocol type is OSPFv3. |
- |
ssh |
Indicates the protocol type is SSH. |
- |
telnet |
Indicates the protocol type is TELNET. |
- |
tftp |
Indicates the protocol type is TFTP. |
- |
cir cir-value |
Specifies the CIR value. |
The value is an integer that ranges from 64 to 65535, in kbit/s. |
cbs cbs-value |
Specifies the CBS value. |
The value is an integer that ranges from 10000 to 4294967295, in bytes. If the cbs is not set, the default cbs-value is 188 times the cir-value. |
Usage Scenario
The default CPCAR value of BGP, BGP4+, FTP, IPv6 FTP, HTTP, HTTPS, IP-CLOUD, ISIS, OSPFv3, OSPF, IKE, IPSEC-ESP, SSH, TFTP, or TELNET protocol is small. When a switch uses these protocols to transfer files or set up connections with other hosts or devices, the number of protocol packets sharply increases in a short period. When the packet rate exceeds the limit, the protocol packets are dropped. The switch may also undergo attacks of other protocols. This affects data transmission and causes service interruption.
You can run the cpu-defend application-apperceive command to enable active link protection, ensuring normal operation of these protocols related services when attacks occur. When a connection is set up, the switch sends packets at the rate of the CPCAR value configured using the linkup-car command. The CPCAR value can be set as required.
Follow-up Procedure
Run the cpu-defend application-apperceive enable command to enable ALP to enable the rate limit set using the linkup-car command. By default, ALP is enabled on FTP, IPv6 FTP, HTTP, IP-CLOUD, HTTPS, IKE, IPSEC-ESP, TFTP, SSH, and TELNET packets and disabled on BGP, BGP4+, ISIS, OSPF, and OSPFv3 packets.
Precautions
You are advised to run the display cpu-defend configuration command to check the CIR value supported by the protocol being used before running the linkup-car command to set the rate limit.
BGP, BGP4+, ISIS, OSPF, and OSPFv3 are disabled when the configuration is initialized. You can set the rate limit using the car command before the protocols are enabled and the linkup-car command after connections are set up and ALP is enabled.
You can set a shared CPCAR value for packets of FTP, IPv6 FTP, SSH, TFTP connections on S2720-EI, S5720I-SI, S5720-LI, S5720S-LI, S5720S-SI, S5720-SI, S5730S-EI, S5730-SI, S6720-LI, S6720S-LI, S6720S-SI, and S6720-SI. For example, the linkup-car packet-type ftp cir cir-value [ cbs cbs-value ] command specifies the CPCAR value for FTP packets when an FTP connection is set up, and also specifies the CPCAR value for packets of IPv6 FTP, SSH, TFTP connections.
Product |
CIR |
CBS |
---|---|---|
S5720-LI, S5720S-LI, S6720-LI, S6720S-LI |
|
|
S5720-SI, S5720I-SI, S5720S-SI |
|
|
S5735-L, S5735S-L, S5735S-L-M |
|
|
S5735-S, S5735S-S, S5735-S-I |
|
|
S2720-EI |
|
|
S5730-SI, S5730S-EI, S6720-SI, S6720S-SI |
|
|
S5720-EI, S6720-EI, S6720S-EI |
|
|
S5720-HI, S5730-HI, S5731-H, S5731S-H, S5731-S, S5731S-S, S6720-HI, S5732-H, S6730-H, S6730S-H, S6730-S, S6730S-S |
|
|