Dell OS10 Storm Control Configuration and Verification - 夜莺博客

Dell OS10 Storm Control Configuration and Verification

A single misbehaving NIC or a looped lab cable can generate enough broadcast traffic to saturate every uplink in a rack, and the symptom - intermittent, unexplainable slowness - is one of the hardest to diagnose after the fact. Storm control on Dell SmartFabric OS10 gives each physical port a hard ceiling on broadcast, multicast and unknown unicast traffic, and the thresholds take thirty seconds to configure. This guide covers the syntax, the percentage-versus-bps decision, the port action, and the verification output that proves traffic is actually being policed.

What Storm Control Polices

OS10 monitors three traffic types independently on L2 and L3 physical interfaces: broadcast frames, multicast frames, and unknown unicast frames (traffic whose destination MAC is not yet in the MAC table). Each type gets its own threshold, and exceeding it triggers the configured action - by default the excess traffic is dropped for the remainder of the interval, which keeps the port up and protects the rest of the network.

Configure storm control on host-facing access ports where a server can misbehave, not on core uplinks where legitimate bursts are expected. Its purpose is containing one noisy endpoint, not shaping a whole fabric.

Percentage-Based Thresholds

OS10# configure terminal
OS10(config)# interface ethernet 1/1/1
OS10(conf-if-eth1/1/1)# storm-control broadcast percentage 5
OS10(conf-if-eth1/1/1)# storm-control multicast percentage 5
OS10(conf-if-eth1/1/1)# storm-control unknown-unicast percentage 5
OS10(conf-if-eth1/1/1)# storm-control broadcast action shutdown
OS10(conf-if-eth1/1/1)# end
OS10# write memory

Percentages are relative to the port's line rate, so a 5% limit means very different absolute bandwidth on a 10G port than on a 1G port. On access ports that is usually what you want - the limit scales with the link. The action shutdown variant errs down the port and requires manual recovery via no shutdown, which is a defensible choice for a server port that should not be allowed to flood at all.

Bit-Per-Second Thresholds

Starting with OS10 10.5.5.5, storm control rates can be expressed in bits per second, which is more predictable across mixed-speed racks:

OS10(conf-if-eth1/1/1)# storm-control broadcast rate-bps 100000000
OS10(conf-if-eth1/1/1)# storm-control multicast rate-bps 100000000
OS10(conf-if-eth1/1/1)# storm-control unknown-unicast rate-bps 100000000

Use bps for uplinks and inter-switch links, where the meaningful number is the absolute bandwidth you are willing to spend on flooded traffic. Use percentage on access ports where one consistent policy across port speeds matters more than an exact figure.

Applying to a Range of Ports

OS10(config)# interface range ethernet 1/1/1-1/1/24
OS10(conf-range-eth1/1/1-1/1/24)# storm-control broadcast percentage 5
OS10(conf-range-eth1/1/1-1/1/24)# storm-control multicast percentage 5
OS10(conf-range-eth1/1/1-1/1/24)# storm-control unknown-unicast percentage 5

Applying at the range level and then overriding individual ports is far more maintainable than per-port configuration. A compliance audit such as the DISA STIG item for Dell OS10 storm control expects it configured on all host-facing ports, so the range approach is also the easiest to prove.

Verification

OS10# show storm-control
OS10# show storm-control interface ethernet 1/1/1
OS10# show interfaces ethernet 1/1/1
OS10# show interfaces ethernet 1/1/1 | grep -i storm
OS10# show running-configuration interface ethernet 1/1/1

The output confirms the configured rate, whether the port is currently in a storm-control state, and the action in effect. On ports configured with action shutdown, a port that has been err-disabled for storm control will report the reason - which turns a mysterious outage into a five-second diagnosis. Compare with the equivalent feature on other vendors: Junos storm control configuration and Dell OS10 port-channel and LACP configuration for the aggregation side.

Choosing Thresholds Without Guesswork

Baseline first. Collect interface rate counters for a week, then set the limit well above the legitimate peak - a 5% limit on a port that legitimately bursts to 4% during backups will cause outage reports that look like network faults. Broadcast rates in a healthy access VLAN are typically well under 1% of line rate; if your baseline is higher than that, find the source before adding a ceiling, because storm control hides the problem rather than fixing it. Remember that unknown unicast is also normal during MAC table churn, and that on a port carrying a hypervisor with many VMs a low unknown-unicast ceiling can generate false positives during VM mobility.

原文链接:https://www.dell.com/support/manuals/en-us/dell-emc-smartfabric-os10/smartfabric-os-user-guide-10-5-2-6/storm-control