1. NE40 V3.1 R2358;
2. NE80E V300R001C01B052
4 pos links 2 GE links
NE80E connects to NE40A using 4 POS interfaces while it's using 2 GE Ports to connect NE40B.one PC access to VPN1 through PE NE40A and the server connected to another PE NE40B Access to the same VPN,VPN1.NE80E works as P router, the working IGP is OSPF.
For PC,the IP address on the other end of link is pingable.but the ping to the IP on NE40B interface which connect to the server fails
The secure configuration to protect IGMP attack on live network, it limited the ICMP uploading bandwidth to 0kbit/s.
1. About No.31 system-bucket,to prevent the attack,it can be set to 4K, the smaller one(0K or 2K)is not suggested.
2. To protect CPU against ICMP attack, ICMP fast reply is a suggestion.
All the ICMP packets which destination is router itself will reply by LPU Card and won't send to CPU to process them, the ICMP packet originated from router itself will not be affected.
3. To change ICMP packet uploading bandwidth.
Apply system car cir
cbs slot type ipv4-redirect-icmp
4. To check NE40 discard count
]display system only-discard
The slot number:6
The Protocol type:IPV4-redirect-icmp
The time of the last packets arrive:17:03:27
The number of present tokens:196526
The number of the discarded packets:269
The number of the passed packets:579274
The bucket alarm enable flag:disable apply system cir 64k cbs 196608