[c-nsp] Drop rule at the end of CoPP conflicts with MAC learning

Nick Hilliard nick at foobar.org
Thu Jun 27 12:58:05 EDT 2013


On 27/06/2013 17:36, "Rolf Hanßen" wrote:
> Is there a way to match that "destination IP = connected IP without entry
> in arp table" traffic ? I found no such option in the syntax.

that is a "glean" packet, and is handled using rate limiters, not CoPP:

> Router(config)#mls rate-limit unicast cef glean ?
>   <10-1000000>  packets per second

more info here:

> http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/prod_white_paper0900aecd802ca5d6.html#wp9000211

Nick




More information about the cisco-nsp mailing list