Cisco Storm Control
I remember when I first saw Storm Control in a config and thought “woah, whats that looks
really confusing”, but really its pretty simple stuff.
We use storm control to rate limit layer 2 traffic, this helps us prevent a subnet from being
flooded with broadcasts, multicasts which would adversely affect the performance of the entire subnet.
Storm Control can only be configured on physical interfaces and will not work on subinterfaces,
or an LACP/PAGP interface.
Configuration
The first command shown limits the broadcast to 200pps, and if this limit is reached will not forward
any more broadcasts until this is reduced to 150pps.
(config-if)#storm-control broadcast level pps 200 150
Multicast and unicast traffic can also be limited, the maximum level can also be entered as a percentage
instead of pps, in the example below multicasts can use up to 5% of the interface bandwidth,
and once that limit is reach no more multicasts will be forwarded until it drops to 4.5% of the total
interface bandwidth
(config-if)#storm-control multicast level 5 4.5
In the final example unicast is limited to 80% of the interface bandwidth but a second value is not
specified, this causes all unicast to be forwarded up to 80% of the bandwidth and it does not force the
traffic to wait until it drops below a second level.
(config-if)#storm-control unicast level 80
The default response for storm control is the drop packets which are over the rate limit, and create a
syslog message, we can also generate a SNMP trap with the command
(config-if)#storm-control action trap
The show commands for this are also really easy :
(config-if)#show storm-control port [unicast|broadcast|multicast]
Configuration Sample :
Understanding Storm Control
Storm control prevents traffic on a LAN from being disrupted by a broadcast,
multicast, or unicast storm on one of the physical interfaces.
A value of 0.0 means that all broadcast, multicast, or unicast traffic on that
port is blocked.
config t
int fa0/1
storm-control broadcast level 80.00 50.00
storm-control multicast level 80.00 50.00
storm-control unicast level 80.00 50.00
storm-control action shutdown
storm-control action trap
Switch(config-if)# storm-control broadcast level 0
Switch(config-if)# storm-control unicast level 0
Switch(config-if)# storm-control multicast level 0
My understanding of “switchport block multicast” is that it blocks flooding of multicast traffic to ports
that are unknown or unjoined for a particular multicast group.
This seems to be a layer 2 multicast control?
“Note Only pure Layer 2 multicast traffic is blocked. Multicast packets that contain IPv4 or IPv6
information in the header are not blocked.”
So same concept, but different layers! The “switchport block” whether unicast or multicast is designed
to affect the Layer2 flooding concepts for unknown unicasts or multicast frames.