Configuring ND VLAN CAR

ND VLAN CAR allows you to limit the rate of ND packets on the attacked interface without affecting other interfaces. This minimizes the impact of attacks on devices and services. After the alarm function is enabled for ND VLAN CAR and the number of ND packets to be sent to the CPU exceeds the threshold configured for ND VLAN CAR, an alarm is reported.

Context

Configure ND VLAN CAR on interfaces of the router.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run slot slot-id

    The slot view is displayed.

  3. Run undo alarm ipv6 nd { na | ns-multicast | ns-unicast } attack disable

    The alarm function is enabled for ND VLAN CAR.

    In VS mode, this feature is supported only by the admin VS.

  4. Run quit

    Return to the system view.

  5. Run interface interface-type interface-number

    The interface view is displayed.

  6. Run ipv6 nd { na | ns-multicast | ns-unicast } rate-limit rate

    The rate limit of ND VLAN CAR for ND packets on an interface is configured.

  7. Run quit

    Return to the system view.

  8. (Optional)
    1. Run slot slot-id

      The slot view is displayed.

    2. Run ipv6 nd { na | ns-multicast | ns-unicast } rate-limit-percent rate-value

      The percentage of the bandwidth of level-2 CAR for ND VLAN CAR in the bandwidth of CP-CAR for ND protocol packets is configured.

      In VS mode, this feature is supported only by the admin VS.

    3. Run quit

      Return to the system view.

Checking the Configuration

After configuring ND VLAN CAR, verify the configuration.

Run the display ipv6 nd { na | ns-multicast | ns-unicast } rate-limit interface { interface-type interface-num | interface-name } command to check the ND packet rate limit of an interface.

Run the display ipv6 nd { na | ns-multicast | ns-unicast } attack interface { interface-type interface-num | interface-name } [ vlan-id vlan-number | pe-vid pe-vid ce-vid ce-vid ] [ history ] command to check the ND attack information on an interface.

Run the display ipv6 nd { na | ns-multicast | ns-unicast } attack slot { slotid | all } [ history ] command to check the ND attack information of a slot.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >