Administrator Guide

Security Commands 1051
no dos-control tcpfrag
Default Configuration
Denial of Service is disabled.
Command Mode
Global Configuration mode
User Guidelines
This command has no user guidelines.
Example
The following example activates TCP Fragment Denial of Service protection.
console(config)#dos-control tcpfrag
rate-limit cpu
Use the rate-limit cpu command to reduce the amount of unknown
unicast/multicast packets forwarded to the CPU on CoS queues 0 and 1.
This command also configures the rate in packets-per-second for the number
of IPv4 and IPv6 data packets trapped to CPU when the packet fails to be
forwarded in the hardware due to unresolved MAC address of the destination
IPv6 node. Packets exceeding the rate limit are silently discarded.
Use the no form of the command to return the rate limit to the default value.
Syntax
rate-limit cpu direction input pps pps-value
no rate-limit cpu direction input pps
pps-value—Range of 100-1024 packets per second (100-3000 for N4000
switches)
Default Configuration
The default is 1024 packets per second
(3000 for N4000 switches)