> I'll be adding a section relatively soon on using Committed Access Rate
> (CAR) to limit ICMP echo/echo-replies to a certain amount.
We're currently doing this on our border routers with reasonable success.
router>sh in hs4/0 rate
Hssi4/0
Input
matches: access-group 198
params: 160000 bps, 8000 limit, 8000 extended limit
conformed 21783346 packets, 3892M bytes; action: transmit
exceeded 6502051 packets, 6074M bytes; action: drop
last packet: 8ms ago, current burst: 6260 bytes
last cleared 1w3d ago, conformed 33000 bps, exceeded 51000 bps
Steinar Haug, Nethelp consulting, sthaug@nethelp.no
This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:13:13 EDT