[c-nsp] Stopping MLD responses & protecting CPU from MLD queries

Lukas Tribus luky-37 at hotmail.com
Thu Jan 26 03:18:49 EST 2017


> I've been testing workarounds based upon filtering the incoming MLD
> query, on a 4500 (Cisco 4948E running 15.1(2)SG) and a 6500 (Cisco
> 6500 w. SUP720-3B running 15.1(2)SY).

Control Plane Policing is probably the way to address this (in case MLD
cannot be properly disabled, I mean).



> Bizarrely, one way of making the 6500 stop responding to MLD queries
> seems to be to send 3000 pps of queries towards it for about 100 seconds,
> around which point it will stop responding to any more until a chassis reload.

Huh, that is a very ciscoesque way to workaround this. Don't tell 'em; they
may document this "workaround" ;)


cheers,
lukas


More information about the cisco-nsp mailing list