CPU Protection Commands
Page 220 7450 ESS System Mangement Guide
Parameters mac-monitoring — Enables per SAP + source MAC address rate limiting using the per-source-rate
from the associated cpu-protection policy.
ip-src-monitoring — Enables per SAP + IP source address rate limiting for certain protocol packets
using the per-source-rate and included-protocols from the associated cpu-protection policy. The
ip-src-monitoring is useful in subscriber management architectures that have routers between the
subscriber and the BNG (router). In layer-3 aggregation scenarios all packets from all
subscribers behind the same aggregation router will arrive with the same source MAC address
and as such the mac-monitoring functionality can not differentiate traffic from different
subscribers.
cpu-protection
Syntax cpu-protection policy-id [mac-monitoring]|[eth-cfm-monitoring [aggregate][car]] |[ip-
src-monitoring]
no cpu-protection
Context config>service>ies>interface>sap
config>service>ies>interface>spoke-sdp
config>service>ies>sub-if>grp-if>sap
config>service>vprn>interface>sap
config>service>vprn>interface>spoke-sdp
config>service>vprn>sub-if>grp-if>sap
Description Use this command to apply a specific CPU protection policy to the associated msap-policy. The
specified cpu-protection policy will automatically be applied to any MSAPs that are create using the
msap-policy.
If no CPU-protection policy is assigned to a SAP, then a default policy is used to limit the overall-rate
according to the default policy. The default policy is policy number 254 for access interfaces, 255 for
network interfaces and no policy for video interfaces.
The no form of the command reverts to the default values.
Default cpu-protection 254 (for access interfaces)
cpu-protection 255 (for network interfaces)
The configuration of no cpu-protection returns the msap-policy to the default policies as shown
above.
Parameters mac-monitoring — Enables per SAP + source MAC address rate limiting using the per-source-rate
from the associated cpu-protection policy.
ip-src-monitoring — Enables per SAP + IP source address rate limiting for certain protocol packets
using the per-source-rate and include-protocols from the associated cpu-protection policy. The ip-src-
monitoring is useful in subscriber management architectures that have routers between the subscriber
and the BNG (router). In layer-3 aggregation scenarios all packets from all subscribers behind the
same aggregation router will arrive with the same source MAC address and as such the mac-monitor-
ing functionality can not differentiate traffic from different subscribers.
eth-cfm-monitoring — Enables the Ethernet Connectivity Fault Management cpu-protection
extensions on the associated SAP/SDP/template.