32-3
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
OL-9639-07
Chapter 32 Configuring Control-Plane Security
Understanding Control-Plane Security
The switch automatically allocates 27 control-plane security policers for CPU protection. At system
bootup, it assigns a policer to each port numbered 0 to 26. The policer assigned to a port determines if
the protocol packets arriving on the port are rate-limited or dropped. A policer of 26 means a drop policer
and is a global policer; any traffic type shown as 26 on any port is dropped. A policer of a value of 0 to
Ta b l e 32-1 Control-Plane Security Actions on Layer 2 Protocol Packets Received on a UNI or ENI
Protocol Default When Feature Is Enabled
When Layer 2
Protocol Tunneling
Is Enabled
1
1. Layer 2 protocol traffic is rate-limited when Layer 2 protocol tunneling is enabled for any protocol on any port.
STP Dropped Rate limited
Note STP can be enabled only on ENIs.
Rate-limited
RSVD_STP (reserved IEEE
802.1D addresses)
Dropped When the Ethernet Link Management Interface
(ELMI) is enabled, globally or on a per-port basis
whichever is configured last, a throttle policer is
assigned to a port. When ELMI is disabled (globally or
on a port, whichever is configured last), a drop policer
is assigned to a port.
PVST+ Dropped – Rate limited
LACP Dropped Rate limited
Note LACP can be enabled only on ENIs.
Rate limited
PAgP Dropped Rate limited
Note PAgP can be enabled only on ENIs.
Rate limited
IEEE 802.1x Dropped Rate limited –
CDP Dropped Rate limited
Note CDP can be enabled only on ENIs.
Rate limited
LLDP Dropped Rate limited
Note LLDP can be enabled only on ENIs.
Rate limited
DTP Dropped – –
UDLD Dropped Rate limited Rate limited
VTP Dropped – Rate limited
CISCO_L2 (any other Cisco
Layer 2 protocols with the MAC
address 01:00:0c:cc:cc:cc)
Dropped – Rate limited if
CD P, DT P, U DL D ,
PAGP, or VTP are
Layer 2 tunneled
KEEPALIVE (MAC address,
SNAP encapsulation, LLC, Org
ID, or HDLC packets)
Rate-limited – –
Ethernet Connectivity Fault
Management (CFM)
No policer
assigned
When CFM is enabled globally, a throttle policer is
assigned to all ports. When CFM is disabled globally,
a NULL policer is assigned to all ports.
–