Re: protecting trunks from flooding

From: Petr Lapukhov (petrsoft@gmail.com)
Date: Wed Apr 05 2006 - 12:33:26 GMT-3


Hello guys,

The best way with 3550 should probably be using
per-VLAN policing (INBOUND direction only)

http://www.cisco.com/univercd/cc/td/doc/product/lan/c3550/12225sec/3550scg/sw
qos.htm#wp1145280

HTH
Petr

2006/4/5, Leigh Harrison <ccileigh@gmail.com>:
>
> Hi there Geert,
>
> Depending on the switches you've got, I'd put in some QoS and ensure
> that you main vlan(s) have guaranteed bandwidth.
>
> LH
>
>
> Geert Nijs wrote:
> > Hi all,
> >
> > What is the best way to protect ONE VLAN on a trunk interface from
> > becoming squuezed away by a DDOS attack on another vlan ?
> > I want to protect bandwidth on some critical VLANs, no matter what
> > happens (DDOS, broadcast storm, STP loops) in the other VLANs.
> >
> > regards,
> >
> > Geert Nijs
> > Service Engineer
> > Networks Lan/Wan
> >
> >
> >
> >
>
#############################################################################
> > ########
> > Simac N.V. trades under the commercial name Simac ICT Belgium.
> > This e-mail and any attached files are confidential and may be legally
> > privileged.
> > If you are not the addressee, any disclosure, reproduction, copying,
> > distribution,
> > or other dissemination or use of this communication is strictly
> prohibited.
> > If you have received this transmission in error please notify Simac
> > immediately
> > and then delete this e-mail.
> >
> > Simac has taken all reasonable precautions to avoid virusses in this
> email.
> > Simac does not accept liability for damage by virusses, for the correct
> and
> > complete
> > transmission of the information, nor for any delay or interruption of
> the
> > transmission,
> > nor for damages arising from the use of or reliance on the information.
> >
> > All e-mail messages addressed to, received or sent by Simac or Simac
> employees
> > are deemed to be professional in nature. Accordingly, the sender or
> recipient
> > of
> > these messages agrees that they may be read by other Simac employees
> than the
> > official
> > recipient or sender in order to ensure the continuity of work-related
> > activities
> > and allow supervision thereof.
> >
>
#############################################################################
> > ########
> >
> > _______________________________________________________________________
> > Subscription information may be found at:
> > http://www.groupstudy.com/list/CCIELab.html
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Mon May 01 2006 - 11:41:56 GMT-3