Show card X icmp <detail/Hidden><br><br><div>I think is the command you want. <br><br><br clear="all">Chris O'Shea<br><br>
<br><br><div class="gmail_quote">2011/9/16 Mariano Juliá <span dir="ltr"><<a href="mailto:mjuliaq@gmail.com">mjuliaq@gmail.com</a>></span><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
Yes, there is a hard coded policer for locally bound ICMP packets.<br>
<br>
As a matter of fact, ICMP packets destined to any local IP address never reach the XCRP, they are always handled by the input traffic card regardless of whether the interface belong to that card or not. So it does for most protocol keepalives although those are not ratelimited.<br>
<br>
I took notes of the ICMP rate limit values, some are in bytes others in packets per second, unfortunately I didn't write down which ones are which.<br>
<br>
ICMP echo request 1000,1500<br>
ICMP echo reply 1000,1500<br>
Net Unreach 10,20<br>
Host Unreach 10,20<br>
port unreach 10,20<br>
DF unreach 1000,2000<br>
admin prohibited 10,20<br>
TTL exceed 100,200<br>
Net Redirect 10,20<br>
host redirect 10,20<br>
Parameter problem 10,20<br>
<br>
If I recall correctly, one of the commands under "show card" has counters for traffic dropped by this policer but I don't have access to a Redback any more so I can't be more precise.<br>
<br>
Regards,<br><font color="#888888">
<br>
Mariano</font><div><div></div><div class="h5"><br>
<br>
On 14/09/2011 14:08, Jim Tyrrell wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Does SEOS have some sort of control plane policing that will drop ICMP<br>
packets in an MPLS environment? I have configured a vpn context but when<br>
testing I'm getting packetloss when pinging the SE600 from our Cisco<br>
routers. I have the following setup:<br>
<br>
R1 -> R2 -> SE600 -> DSL line (L2TP session)<br>
<br>
R1 & R2 can ping each other fine, and they can also ping the DSL line<br>
with 0 packetloss, but when I ping between the Cisco and SE600 I'm<br>
getting packetloss:<br>
<br>
<br>
ping vrf test 172.16.10.3 repeat 100<br>
Sending 100, 100-byte ICMP Echos to 172.16.10.3, timeout is 2 seconds:<br>
!!!!!!!!!!.!!!!!!!!!!.!!!!!!!!<u></u>!!.!!!!!!!!!!.!!!!!!!!!!.!!!!!<u></u>!!!!!.!!!!!!!!!!.!!!!!!!!!!.!!<u></u>!!!!!!!!.!<br>
<br>
Success rate is 91 percent (91/100), round-trip min/avg/max = 1/1/4 ms<br>
<br>
It seems to be quite regular, and doesnt happen when pinging through the<br>
SE600 to the DSL line so I'm thinking there is some kind of ratelimiting<br>
on the SE600 itself?<br>
<br>
Thanks.<br>
<br>
Jim.<br>
______________________________<u></u>_________________<br>
redback-nsp mailing list<br>
<a href="mailto:redback-nsp@puck.nether.net" target="_blank">redback-nsp@puck.nether.net</a><br>
<a href="https://puck.nether.net/mailman/listinfo/redback-nsp" target="_blank">https://puck.nether.net/<u></u>mailman/listinfo/redback-nsp</a><br>
</blockquote>
______________________________<u></u>_________________<br>
redback-nsp mailing list<br>
<a href="mailto:redback-nsp@puck.nether.net" target="_blank">redback-nsp@puck.nether.net</a><br>
<a href="https://puck.nether.net/mailman/listinfo/redback-nsp" target="_blank">https://puck.nether.net/<u></u>mailman/listinfo/redback-nsp</a><br>
</div></div></blockquote></div><br></div>