clear hostdos-counters Configuring Flow Setup Throttling (FST)
Enterasys Matrix DFE-Gold Series Configuration Guide 24-25
Configuring Flow Setup Throttling (FST)
About FST
FlowSetupThrottling(FST)isaproactivefeaturedesignedtomitigateDoSattacksbeforethe
viruscanwreakhavoconthenetwork.FSTdirectlycombatstheeffectsofDoSattacksbylimiting
thenumberofneworestablishedflowsthatcanbeprogrammedonanyindividualswitchport.
Thisisachieved
bymonitoringthenewflowarrivalrateand/orcontrollingthemaximumnumber
ofallowableflows.
FSTlimitsthevulnerabilityofconnectionattacksonthe networkbyallowingadministratorsto:
• GloballyenableFSTontheswitchandonaport‐by‐portbasis.
• Configurethemaximumflowsallowedperuserclassification(port
type)andtheactionsthat
willoccurwhenflowlimitsarereached.
• Assignauserclassificationtoeachinterface.
• ControlthegenerationofSNMPnotifications.
• Controlthetime(inseconds)towaitbeforegeneratinganothernotificationofthesametype
onthesameinterface.
• Controllinkstatus.
Purpose
ToreviewandconfigureFlowSetupThrottling.
Commands
For information about... Refer to page...
show flowlimit 24-26
set flowlimit 24-26
set flowlimit limit 24-27
clear flowlimit limit 24-28
set flowlimit action 24-28
clear flowlimit action 24-29
show flowlimit class 24-30
set flowlimit port 24-31
clear flowlimit port class 24-32
set flowlimit shutdown 24-32
set flowlimit notification 24-33
clear flowlimit notification interval 24-34
clear flowlimit stats 24-34