The flowspec protocol-protect disable command disables BGP FlowSpec protocol protection.
The undo flowspec protocol-protect disable command restores the default configuration.
By default, the BGP FlowSpec protocol protection function is enabled.
Usage Scenario
Packets to be sent to the CPU and used to establish protocol sessions may match BGP FlowSpec routes in which the action is deny or redirect. In this case, packets are discarded or redirected, causing session establishment failures. To prevent such failures, the BGP FlowSpec protocol protection function can be used. With this function that is enabled by default, the preceding matching packets are not discarded or redirected so that protocol session can be properly established. If the system does not need the BGP FlowSpec protocol protection function, run the flowspec protocol-protect { ipv4 | ipv6 } disable command in the system view to disable the function.
Precautions
In VS mode, this command is supported only by the admin VS.
<HUAWEI> system-view [~HUAWEI] undo flowspec protocol-protect ipv6 disable
<HUAWEI> system-view [~HUAWEI] undo flowspec protocol-protect ipv4 disable
<HUAWEI> system-view [~HUAWEI] flowspec protocol-protect ipv6 disable
<HUAWEI> system-view [~HUAWEI] flowspec protocol-protect ipv4 disable