Configuring Congestion Control And Security Policies - Huawei SmartAX MA5603T Configuration Manual

Access module
Hide thumbs Also See for SmartAX MA5603T:
Table of Contents

Advertisement

SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide

13.3.4.7 Configuring Congestion Control and Security Policies

This topic describes how to configure global priority-based scheduling policies for queues to
ensure service reliability and configure global security policies to ensure service security.
Context
Congestion control uses queue scheduling technology to map packets sent from the same port
into multiple queues and process packets in each queue based on priority. Congestion control is
recommended.
Security policies cover system security, user security, and service security, which ensure normal
running of services.
NOTE
Enable security features based on service types. For details, see
Procedure
l
l
l
Issue 01 (2014-04-30)
Configure queue scheduling.
Based on
13.2.3 Principle of QoS Data
scheduling and are mapped to queues based on priorities.
huawei(config)#queue-scheduler strict-priority
huawei(config)#cos-queue-map cos0 0 cos1 1 cos2 2 cos3 3 cos4 4 cos5 5 cos6 6
cos7 7
//System default
Configure system security.
– Enable deny of service (DoS) anti-attack on both the OLT and optical network units
(ONUs).
1.
Run the security anti-dos enable command to globally enable DoS anti-attack.
2.
Run the security anti-dos control-packet policy command to configure a
protocol packet processing policy that will be used when a DoS attack occurs.
3.
Run the security anti-dos control-packet rate command to configure the
threshold for the rate of sending protocol packets to the CPU.
– Enable IP address anti-attack on both the OLT and ONUs.
Run the security anti-ipattack enable command to enable IP address anti-attack.
Configure user security.
– Enable MAC address anti-flapping on both the OLT and ONUs.
Run the security anti-macduplicate enable command to enable MAC address anti-
flapping.
– Enable MAC address anti-spoofing on both the OLT and ONUs.
1.
In global config mode, run the security anti-macspoofing enable command to
globally enable MAC address anti-spoofing.
2.
Enable MAC address anti-spoofing at VLAN level in global config mode or
service profile mode:
a.
In global config mode, run the security anti-macspoofing vlan command
to enable MAC address anti-spoofing.
b.
Perform the following operations to enable MAC address anti-spoofing in
service profile mode:
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
13 FTTO Configuration (Large-sized Enterprise Access)
13.2.5 Principle of Security Data
Plan, all packets use strict priorities for queue
Plan.
1322

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Smartax ma5600tSmartax ma5608t

Table of Contents