Users Guide
The backplane ports can have a maximum of 4 control queues. So, when we have more than ‘n’ CMIC queues for well-known protocols and
n > 4, then streams on ‘n’ CMIC queues must be multiplexed on 4 control queues on back-plane ports and on the Master unit, these
streams must be de-multiplexed to ‘n’ CMIC queues on the Master CPU.
After control packets reach the CPU through the CMIC port, the software schedules to process trac on each 12 CPU queues. This
aspect must be ensured even in case of stand-alone systems and there is no dependency with stacking.
Policing provides a method for protecting CPU bound control plane packets by policing packets transmited to CPU with a specied rate
and from undesired or malicious trac. This is done at each CPU queue on each unit.
FP Entries for Distribution of NDP Packets to Various CPU Queues
• At present generic mac based entries in system ow region will take IPv6 packets to CPU.
• OSPFv3 – 33:33:0:0:0:5 – Q7
• - 33:33:0:0:0:6 – Q7
• IPv6 Multicast – 33:33:0:0:0:0 – Q1
• Add/remove specic ICMPv6 NDP protocol entry when user congures the rst ipv6 address in the front panel port
• Distribute ICMPv6 NS/RS packets to Q5.
• Distribute ICMPv6 NA/RA packets to Q6.
FP is installed for all Front panel ports.
NDP Packets
Neighbor discovery protocol has 4 types of packets NS, NA, RA, RS. These packets need to be taken to CPU for neighbor discovery.
• Unicast NDP packets:
• Packets hitting the L3 host/route table and discovered as local terminated packets/CPU bound trac. For CPU bound trac route
entry have CPU action. Below are packets are CPU bound trac.
• Packets destined to chassis.
• Route with Unresolved Arp
• Unknown trac in IP Subnet range
• Unknown trac hitting the default route entry.
• Multicast NDP packets
• NDP packets with destination MAC is multicast
• DST MAC 33:33:XX:XX:XX:XX
• NDP Packets in VLT peer routing enable
• VLT peer routing enable cases each VLT node will have route entry for link local address of both self and peer VLT node. Peer VLT
link local entry will have egress port as ICL link. And Actual link local address will have entry to CopyToCpu. But NDP packets
destined to peer VLT node needs to be taken to CPU and tunneled to the peer VLT node..
• NDP packets in VLT peer routing disable case
• NDP packets intended to peer VLT chassis taken to CPU and tunnel to peer.
The following table describes the protocol to queue mapping with the CPU queues increased to be 12.
224
Control Plane Policing (CoPP)