Users Guide

Security Commands 1146
User Guidelines
This command has no user guidelines.
Example
The following example activates TCP Fragment Denial of Service protection.
console(config)#dos-control tcpfrag
rate-limit cpu
Use the rate-limit cpu command to reduce the amount of unknown
unicast/multicast packets forwarded to the CPU on CoS queues 0 and 1.
This command also configures the rate in packets-per-second for the number
of IPv4 and IPv6 data packets trapped to CPU when the packet fails to be
forwarded in the hardware due to unresolved MAC address of the destination
IPv6 node. Packets exceeding the rate limit are silently discarded.
Use the no form of the command to return the rate limit to the default value.
Syntax
rate-limit cpu direction input pps pps-value
no rate-limit cpu direction input pps
pps-value—Range of 50-1024 packets per second
Default Configuration
The default is 1024 packets per second
Command Modes
Global Configuration mode
User Guidelines
Unknown multicast and IPv4/IPv6 data packets destined to hosts in the
connected networks on the router for which the MAC address is not resolved
are trapped to CPU to trigger the ARP/neighbor discovery resolution of those
hosts.