Hello All:
I was sure that I posted this question before but can’t find it on the forum so am reposting it here.
I want to allow pings on say PPP1 but I don’t want to allow an infinite number of pings per unit time. Cisco allows this command for a particular interface:
rate-limit input access-group 102 8000 1500 2000 conform-action transmit exceed-action drop
access-list 102 permit icmp any any echo
access-list 102 permit icmp any any echo-reply
So you place that rate-limit command on an interface and it prevent too many ping replies per second. In this case:
Input, that is pings coming in,
access-grou 102, ICMP echo replies and outgoing as well,
8000 bps, average rate per second,
1500 bps is the burst size,
2000 is burst max,
Transmit is the function,
Exceed-action is the condition,
Drop, what to do if the condition is exceeded.
In short this limits the pings replies to ~10-15 per second maximum. If you ping flood this interface you’ll get a max of 15 back, no more.
Does Digi have something like this?
Cheers,
John