Cisco UBR10012在日常维护的过程中出现high cpu问题,经检查是DHCPD Receive进程占用过高。
说明设备受到了过量的DHCP报文,为避免影响正常业务流量,配置DRL(Divert Rate Limit)对
UBR10012的CPU进行保护。
对DRL的解释和配置方法可以参考以下官方文档:
在UBR10012中DRL可以用于控制WAN口流量和RF口流量。具体实现脚本如下:
WANside流量:
service divert-rate-limit ip fib_rp_glean rate 20 limit 20
service divert-rate-limit ip fib_rp_dest rate 20 limit 20
service divert-rate-limit ip fib_rp_punt rate 20 limit 20
service divert-rate-limit max-rate wan fib_rp_dest rate 500 limit 100
RFside流量:(应用于RF mac domain)
interface Cable5/0/0
cable divert-rate-limit rate 10 limit 10
interface Cable5/0/1
cable divert-rate-limit rate 10 limit 10
.........................
添加trust-site:(此部分流量不受DRL控制,主要用于从DHCP server过来的报文)
service divert-rate-limit trusted-site X.X.X.X 255.255.255.255 tos 0 mask 0 vrf XXX
service divert-rate-limit trusted-site X.X.X.X 255.255.255.255 tos 0 mask 0 vrf XXX
service divert-rate-limit trusted-site X.X.X.X 255.255.255.255 tos 0 mask 0 vrf XXX
service divert-rate-limit trusted-site X.X.X.X 255.255.255.255 tos 0 mask 0 vrf XXX
具体数值按照需求修改。