- Written by Josh Pfosi
- Posted on June 11, 2019
- Updated on July 24, 2026
- 19561 Views
This feature adds support for CPU traffic policy capable of matching and acting on IP traffic which would otherwise hit the CPU. This policy is capable of permitting traffic from trusted sources, while rejecting untrusted traffic. It supports matching on a variety of IP packet header information such as DSCP, L4 port values, fragmentation bits, etc. as well as a number of actions such as permit, deny, and police. To prevent a malicious source from overloading the CPU, this traffic policy will take effect in the switching hardware, before the traffic is processed by the kernel. This feature provides a shorthand syntax for securing L3 protocol peers, in particular, BGP neighbors.
