No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Configuration Guide - IP Service

S7700 and S9700 V200R013C00

This document describes the configurations of IP service, including IP address, ARP, DHCP, DNS, mDNS gateway, mDNS relay, UDP Helper, IP performance optimization, IPv6, DHCPv6, IPv6 DNS, IPv6 over IPv4 tunnel and IPv4 over IPv6 tunnel.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Configuring the Device Not to Send NS Packets Destined for Other Devices to the CPU

Configuring the Device Not to Send NS Packets Destined for Other Devices to the CPU

Context

If an interface receives a large number of NS packets whose destination IPv6 addresses are different from the IPv6 address of this interface and sends these NS packets to the CPU for processing, the CPU usage is high and the CPU cannot process services properly.

To prevent this issue, you can configure the device to directly forward NS packets destined for other devices without sending them to the CPU. This improves the device's capability of defending against packet attacks.

NOTE:

Only X series cards support this command.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run interface vlanif vlan-id

    The VLANIF interface view is displayed.

  3. Run nd optimized-passby enable

    The device is configured not to send NS packets destined for other devices to the CPU.

    By default, a device does not send NS packets destined for other devices to the CPU.

    If the nd snooping enable is executed in system view, or if IPv6 protocol is Down on the VLANIF interface, the configuration of disabling the device from sending NS packets destined for other devices to the CPU does not take effect on the VLANIF interface.

Verifying the Configuration

Run the display nd optimized-passby status command to verify whether the device is configured not to send NS packets destined for other devices to the CPU and whether the configuration takes effect.

Translation
Download
Updated: 2019-04-20

Document ID: EDOC1100065743

Views: 28806

Downloads: 31

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Share
Previous Next