Got it

cpu-defend

Created: Oct 31, 2019 02:01:17Latest reply: Oct 31, 2019 02:04:05 371 1 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi all,

Run the following commands to restrict the OSPF neighbor relationship establishment. If the neighbor relationship has been established, the OSPF neighbor relationship is still in full state after the policy is applied. If the OSPF process is reset, the neighbor relationship cannot be established. Why does the cpu-defense policy take effect only after the process is reset?

[RouterA] acl 3000

[RouterA-acl-adv-3000]rule 1 permit ip destination 224.0.0.0 0.0.0.255

[RouterA] cpu-defend policy 1

[RouterA-cpu-defend-policy-1] blacklist acl 3000

[RouterA-cpu-defend-policy-1] car blacklist cir 0

[RouterA] slot 1

[RouterA-slot-1] cpu-defend-policy 1

Thanks.

Featured Answers

Recommended answer

Popeye_Wang
Admin Created Oct 31, 2019 02:04:05

Hi Steelbule,

This design should be reasonable because the OSPF neighbor relationship has been established and the session already exists. The cpu-defend cannot cut off the running services according to the design. Only the policy is delivered to the interface board to prevent the subsequent establishment of the OSPF neighbor relationship. The first is to protect services and prevent service interruption caused by incorrect configurations. The second is to restart the OSPF process to confirm that the cpu-defend policy need to be delivered. In this way, the effect of double protection is achieved.

Similarly, if you configure the VTY ACL to restrict login, the ACL deny rule contains the IP address of your login ip, you are still occupying a VTY session. The ACL in the vty does not directly kick you out. Only when you exit the session, the ACL will restrict your next login.


View more
  • x
  • convention:

All Answers

Hi Steelbule,

This design should be reasonable because the OSPF neighbor relationship has been established and the session already exists. The cpu-defend cannot cut off the running services according to the design. Only the policy is delivered to the interface board to prevent the subsequent establishment of the OSPF neighbor relationship. The first is to protect services and prevent service interruption caused by incorrect configurations. The second is to restart the OSPF process to confirm that the cpu-defend policy need to be delivered. In this way, the effect of double protection is achieved.

Similarly, if you configure the VTY ACL to restrict login, the ACL deny rule contains the IP address of your login ip, you are still occupying a VTY session. The ACL in the vty does not directly kick you out. Only when you exit the session, the ACL will restrict your next login.


View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.