{"id":2101,"date":"2011-05-07T21:51:36","date_gmt":"2011-05-07T21:51:36","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=2101"},"modified":"2016-08-09T12:08:27","modified_gmt":"2016-08-09T12:08:27","slug":"cisco-storm-control","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2011\/05\/07\/cisco-storm-control\/","title":{"rendered":"Cisco Storm Control"},"content":{"rendered":"<p><span style=\"color: #000000;\">I remember when I first saw <span style=\"color: #000080;\">Storm Control<\/span> in a config and thought \u201c<span style=\"color: #800000;\">woah<\/span>, whats that looks<br \/>\nreally confusing\u201d, but really its pretty <span style=\"color: #800000;\">simple stuff<\/span>.<\/span><\/p>\n<p><span style=\"color: #000000;\">We use<span style=\"color: #800000;\"> storm control<\/span> to rate limit layer 2 traffic, this helps us prevent a subnet from being<br \/>\n<span style=\"color: #800000;\">flooded<\/span> with <span style=\"color: #800000;\">broadcasts<\/span>, <span style=\"color: #800000;\">multicasts <\/span>which would adversely affect the performance of the entire subnet.<\/span><\/p>\n<p><span style=\"color: #800000;\">Storm Control <\/span><span style=\"color: #000000;\">can only be configured on<\/span> <span style=\"color: #000080;\">physical interfaces<\/span> <span style=\"color: #000000;\">and will not work on<\/span> <span style=\"color: #000080;\">subinterfaces<\/span>,<br \/>\n<span style=\"color: #000000;\"> or an LACP\/PAGP interface<\/span>.<\/p>\n<p><strong><span style=\"color: #000000;\">Configuration<\/span><\/strong><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #800000;\">The first command<\/span> shown limits the<span style=\"color: #000080;\"> broadcast<\/span> to 200pps, and if this limit is reached will not forward<br \/>\nany more broadcasts until this is reduced to 150pps.<\/span><\/p>\n<p><span style=\"color: #000000;\">(config-if)#<strong>storm-control broadcast level pps 200 150<\/strong><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #800000;\">Multicast<\/span> and <span style=\"color: #800000;\">unicast<\/span> traffic can also be limited, the maximum level can also be entered as a <span style=\"color: #800000;\">percentage<\/span><br \/>\ninstead of <span style=\"color: #800000;\">pps<\/span>, in the example below multicasts can use up to <span style=\"color: #000080;\">5%<\/span> of the <span style=\"color: #800000;\">interface bandwidth<\/span>,<br \/>\nand once that\u00a0limit is reach no more <span style=\"color: #000080;\">multicasts<\/span> will be forwarded until it drops to <span style=\"color: #000080;\">4.5%<\/span> of the total<br \/>\ninterface bandwidth<\/span><\/p>\n<p><span style=\"color: #000000;\">(config-if)#<strong>storm-control multicast level 5 4.5<\/strong><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #800000;\">In the final example<\/span> <span style=\"color: #000080;\">unicast<\/span> is limited to <span style=\"color: #000080;\">80%<\/span> of the interface bandwidth but a second value is not<br \/>\nspecified, this causes all unicast to be forwarded up to 80% of the bandwidth and it does not force the<br \/>\ntraffic to wait until it drops below a second level.<\/span><\/p>\n<p><span style=\"color: #000000;\">(config-if)#<strong>storm-control unicast level 80<\/strong><\/span><\/p>\n<p><span style=\"color: #000000;\">The default response for<span style=\"color: #800000;\"> storm control<\/span> is the drop packets which are over the rate limit, and create a<br \/>\n<span style=\"color: #800000;\"> syslog message<\/span>, we can also generate a S<span style=\"color: #000080;\">NMP trap<\/span> with the command<\/span><\/p>\n<p><span style=\"color: #000000;\">(config-if)#<strong>storm-control action trap<\/strong><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #000080;\">The show commands for this are also really easy<\/span> :<br \/>\n<span style=\"color: #000000;\"> (config-if)#<strong>show storm-control<\/strong> <em>port <\/em>[<strong>unicast<\/strong>|<strong>broadcast<\/strong>|<strong>multicast<\/strong>]<\/span><\/span><\/p>\n<p><span style=\"color: #800000;\">Configuration Sample<\/span> :<\/p>\n<h3><span style=\"color: #000000;\">Understanding Storm Control<\/span><\/h3>\n<pre><\/pre>\n<p><span style=\"color: #000000;\">Storm control prevents traffic on a LAN from being disrupted by a<span style=\"color: #800000;\"> broadcast<\/span>, <\/span><br \/>\n<span style=\"color: #000000;\"><span style=\"color: #800000;\">multicast<\/span>, or <span style=\"color: #800000;\">unicast<\/span> storm on one of the physical interfaces<\/span>.<\/p>\n<p><span style=\"color: #000000;\">A value of 0.0 means that all <span style=\"color: #800000;\">broadcast<\/span>, <span style=\"color: #800000;\">multicast<\/span>, or <span style=\"color: #800000;\">unicast<\/span> traffic on that <\/span><br \/>\n<span style=\"color: #000000;\">port is blocked.<\/span><\/p>\n<p><span style=\"color: #000000;\">config t <\/span><br \/>\n<span style=\"color: #000000;\">int fa0\/1 <\/span><br \/>\n<span style=\"color: #000080;\">storm-control broadcast level 80.00 50.00 <\/span><br \/>\n<span style=\"color: #000080;\"> storm-control multicast level 80.00 50.00 <\/span><br \/>\n<span style=\"color: #000080;\"> storm-control unicast level 80.00 50.00 <\/span><br \/>\n<span style=\"color: #000080;\"> storm-control action shutdown <\/span><br \/>\n<span style=\"color: #000080;\"> storm-control action trap<\/span><\/p>\n<p><span style=\"color: #000000;\">Switch(config-if)#<span style=\"color: #000080;\"> storm-control broadcast level 0 <\/span><\/span><br \/>\n<span style=\"color: #000000;\">Switch(config-if)# <span style=\"color: #000080;\">storm-control unicast level 0 <\/span><\/span><br \/>\n<span style=\"color: #000000;\">Switch(config-if)# <span style=\"color: #000080;\">storm-control multicast level 0<\/span><\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"color: #000000;\">My understanding of &#8220;<span style=\"color: #800000;\">switchport block multicast<\/span>&#8221; is that it blocks flooding of <span style=\"color: #800000;\">multicast<\/span> traffic to ports<br \/>\nthat are unknown or unjoined for a particular multicast group. <\/span><\/span><\/p>\n<p><span style=\"color: #000000;\">This seems to be a <\/span><span style=\"color: #800000;\">layer 2 multicast control<\/span>?<br \/>\n&#8220;<span style=\"color: #000000;\"><strong>Note <\/strong>Only pure Layer 2 multicast traffic is blocked. Multicast packets that contain IPv4 or IPv6<br \/>\ninformation in the header are not blocked<\/span>.&#8221;<\/p>\n<p><span style=\"color: #000000;\"> So same concept, but different layers!\u00a0 The &#8220;switchport block&#8221; whether unicast or multicast is designed<br \/>\nto affect the Layer2 flooding concepts for unknown unicasts or multicast frames.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I remember when I first saw Storm Control in a config and thought \u201cwoah, whats that looks really confusing\u201d, but really its pretty simple stuff. We use storm control to rate limit layer 2 traffic, this helps us prevent a subnet from being flooded with broadcasts, multicasts which would adversely affect the performance of the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[654],"class_list":["post-2101","post","type-post","status-publish","format-standard","hentry","category-cisco-routers","tag-storm-control"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/2101","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=2101"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/2101\/revisions"}],"predecessor-version":[{"id":5080,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/2101\/revisions\/5080"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=2101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=2101"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=2101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}