The l2protocol-tunnel drop-threshold command configures a drop threshold for Layer 2 protocol data units (PDUs) on an interface enabled with Layer 2 protocol tunneling.
The undo l2protocol-tunnel drop-threshold command restores the default drop threshold for Layer 2 PDUs on an interface enabled with Layer 2 protocol tunneling.
By default, the drop threshold is 0, meaning that the drop threshold for Layer 2 protocol data units (PDUs) on an interface enabled with Layer 2 protocol tunneling is not set.
Parameter | Description | Value |
---|---|---|
rate |
Specifies the threshold for dropping Layer 2 PDUs per second on an interface enabled with Layer 2 protocol tunneling. |
The value is an integer ranging from 1 to 4096, in packets per second. |
protocol |
Specifies the Layer 2 protocol of which the drop threshold is configured for Layer 2 PDUs. |
The protocol as follows:
One or up to all of the preceding Layer 2 protocols can be specified. |
Layer 2 100GE interface view, 100GE interface view, Layer 2 10GE interface view, 10GE interface view, 25GE-L2 view, 25GE interface view, 400GE Layer 2 sub-interface view, 400GE-L2 view, 400GE interface view, Layer 2 40GE interface view, 40GE interface view, 50GE Layer 2 sub-interface view, Layer 2 50GE interface view, 50GE interface view, Eth-Trunk Layer 2 sub-interface view, Layer 2 Eth-Trunk interface view, Eth-Trunk interface view, FlexE sub-interface view, FlexE interface view, GE Layer 2 sub-interface view, Layer 2 GE interface view, GE optical interface view, GE interface view, GE electrical interface view, Layer 2 sub-interface view, Sub-interface view, Interface group view
Usage Scenario
To protect interfaces enabled with Layer 2 protocol tunneling against protocol packet attacks, run the l2protocol-tunnel drop-threshold command to configure a drop threshold for Layer 2 PDUs on the interfaces.
The interfaces drop excess Layer 2 PDUs when the number of Layer 2 PDUs received in 1s exceeds the configured drop threshold.Prerequisites
Layer 2 protocol tunneling has been enabled using the l2protocol-tunnel vlan or l2protocol-tunnel enable command.
Follow-up Procedure
Run the display l2protocol-tunnel statistics command to view statistics about tunneled Layer 2 PDUs on an interface enabled with Layer 2 protocol tunneling and use the statistics as a reference for traffic statistics and fault diagnosis.
Precautions
Before using the l2protocol-tunnel drop-threshold command, note the following:
<HUAWEI> system-view [~HUAWEI] interface GigabitEthernet 0/1/1 [~HUAWEI-GigabitEthernet0/1/1] portswitch [*HUAWEI-GigabitEthernet0/1/1] l2protocol-tunnel stp enable [~HUAWEI-GigabitEthernet0/1/1] l2protocol-tunnel drop-threshold 10 stp