[c-nsp] IOS XR 4.3.4, control-plane policing, and NTP

Gert Doering gert at greenie.muc.de
Sat Aug 2 13:43:21 EDT 2014


Hi,

On Sat, Aug 02, 2014 at 07:40:34PM +0200, Daniel Suchy wrote:
> LPTS limits (in hardware) ammount of packets from (each) linecard to
> LC/RP CPU - with combination with service ACL you mentioned before can
> be service reasonably protected against misuse.

Understood.  Still doesn't explain why, for example, SNMP is handled
by MPP "all" rules while NTP isn't, thus forcing you to have extra NTP
ACLs.

(I *like* MPP a lot :-) ).

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert at greenie.muc.de
fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 291 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/cisco-nsp/attachments/20140802/b5158b13/attachment.sig>


More information about the cisco-nsp mailing list