cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
271
Views
0
Helpful
1
Replies

DoS and rate limit

mpalis
Level 1
Level 1

have a few STM-1 lines connected to upstream providers and I will like to configure on the interfaces permanent rate-limit commands in order to rate limit the number of packets in case of a DoS attack. We are constantly measuring the number of packets using Cricket which under normal network behavior is about 40K packets per second. (maximum). Under a DoS attack the number of packets passing through increases to about 60k or even 70K and we are experiencing performance problems.

Any suggestion of how to apply constant rate-limit on number of packets per interface will be appreciated

1 Reply 1

ehirsel
Level 6
Level 6

This link may be of help:

http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_tech_note09186a00800fb50a.shtml

It deals with using CAR during a DOS attack.

Let me know if this was of use, or if you need any more help.