Showing posts with label 3560. Show all posts
Showing posts with label 3560. Show all posts

Wednesday, February 11, 2009

Storm-control differences between 6500/7600 and other switches

3550/3560/3750
The graph in the following figure shows broadcast traffic patterns on an interface over a given period of time. In this example, the broadcast traffic being forwarded exceeded the configured threshold between time intervals T1 and T2 and between T4 and T5. When the amount of specified traffic exceeds the threshold, all traffic of that kind is dropped for the next time period. Therefore, broadcast traffic is blocked during the intervals following T2 and T5. At the next time interval (for example, T3), if broadcast traffic does not exceed the threshold, it is again forwarded.


Conclusion : if storm-control threshold is exceeded during a 1 sec interval, broadcast traffic is dropped for the whole next interval(s).


6500/7600
Traffic storm control monitors the level of each traffic type for which you enable traffic storm control in 1-second traffic storm control intervals. Within an interval, when the ingress traffic for which traffic storm control is enabled reaches the traffic storm control level that is configured on the port, traffic storm control drops the traffic until the traffic storm control interval ends.

The graph in the following figure shows the broadcast traffic patterns on a LAN interface over a given interval. In this example, traffic storm control occurs between times T1 and T2 and between T4 and T5. During those intervals, the amount of broadcast traffic exceeded the configured threshold.



Conclusion : if storm-control threshold is exceeded during a 1 sec interval, broadcast traffic is dropped from the time the threshold was exceeded until the end of the current interval.

That means that on 3550/3560/3750 switches you can have broadcast traffic above the storm-control threshold within a 1 sec interval.

Besides the above inner-workings of storm-control, 3550/3560/3750 switches support rising and falling thresholds, different actions for storm-control and thresholds based on pps/bps levels.

Different architectures, different implementations.

Friday, January 11, 2008

How to permit ARP traffic between only two hosts

There are (at least) 2 methods to permit ARP traffic between only 2 hosts. Vlan Maps & ARP Inspection.

Host 1 (IP: 1.1.1.46 MAC: 0000.0c46.4646)

Host 2 (IP: 1.1.1.64 MAC: 0000.0c64.6464)

Using Vlan Maps


mac access-list extended ARP
permit host 0000.0c46.4646 host 0000.0c64.6464 0x806 0x0
permit host 0000.0c64.6464 host 0000.0c46.4646 0x806 0x0
permit host 0000.0c46.4646 host ffff.ffff.ffff 0x806 0x0
permit host 0000.0c64.6464 host ffff.ffff.ffff 0x806 0x0
deny any any 0x806 0x0
permit any any
!
vlan access-map VLAN_46_ARP 10
action forward
match mac address ARP
!
vlan filter VLAN_46_ARP vlan-list 46

0x806 is the ethertype for arp packets, ffff.ffff.ffff is the L2 broadcast address used by arp when a host is sending the initial arp request in order to find the mac address of the other host.


Using ARP Inspection

arp access-list VLAN_46_ARP
permit ip host 1.1.1.46 mac host 0000.0c46.4646
permit ip host 1.1.1.64 mac host 0000.0c64.6464
!
ip arp inspection vlan 46
ip arp inspection filter VLAN_46_ARP vlan 46


The arp access-list includes the mappings between the ip and the mac of each host that should be allowed to send arp packets.

 
Creative Commons License
This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License.
Creative Commons License
This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Greece License.