What do you guys use for uplinks rate limiting on access stacks/switches?
2% on access ports and 5-10% on access uplinks?
And the downside of rate limiting is the notify, there is no snmp-trap,syslog-msg or dram-log-msg saying that rate-limiting is dropping traffic due to the threshold. For now can use rmon traps but anyone using anything smart?
Ow and worth mentioning, when using (ext)-cp-limit it only works if you've an active ERS ip-interface in the vlan traversing the port.
Besides the mentioned hardening features no loop-detect, use SLPP, use VLACP, use BPDU-filtering on access as well as STP-FastStart.
Leaving cp-limit to default values 10k/pps, using cp-limit on the ports. Only when having a multicast ingress stream adjusting cp-limit and taking ext-cp-limit of the port
regards
q