13-Layer 3—IP Services Command Reference

HomeSupportReference GuidesCommand ReferencesH3C SecPath Firewall Series Command References(V7)-6W40213-Layer 3—IP Services Command Reference
11-Multi-CPU packet distribution commands
Title Size Download
11-Multi-CPU packet distribution commands 40.11 KB

Multi-CPU packet distribution commands

forwarding policy

Use forwarding policy to specify a multi-CPU packet distribution policy.

Use undo forwarding policy to restore the default.

Syntax

forwarding policy { per-flow [ three-tuple ] | per-packet }

undo forwarding policy

Default

The device uses the flow-based policy, which identifies a flow by source IP address, destination IP address, source port number, destination port number, and protocol number.

Views

System view

Predefined user roles

network-admin

context-admin

Parameters

per-flow: Specifies the flow-based forwarding. The device identifies a data flow by the five-tuple, and forwards packets of the same flow to one CPU. The CPU processes flow packets by following the first-in first-out rule.

three-tuple: Identifies a data flow by the three-tuple (source IP address, destination IP address, and protocol number).

The following compatibility matrix shows the support of hardware platforms for this keyword:

 

Hardware

Parameter compatibility

F5010, F5020, F5020-GM, F5040, F5000-C, F5000-S

No

F5030, F5030-6GW, F5060, F5080, F5000-AI-20, F5000-AI-40, F5000-V30, F5000-M, F5000-A

Yes

F1000-AI-20, F1000-AI-30, F1000-AI-50

No

F1000-AI-60, F1000-AI-70, F1000-AI-80, F1000-AI-90

Yes

F1003-L, F1005-L, F1010-L

Yes

F1005, F1010

Yes

F1020, F1020-GM, F1030, F1030-GM, F1050, F1060, F1070, F1070-GM, F1070-GM-L, F1080, F1000-V70

No

F1090

Yes

F1000-AK1110, F1000-AK1120, F1000-AK1130, F1000-AK1140

Yes

F1000-AK1212, F1000-AK1222, F1000-AK1232, F1000-AK1312, F1000-AK1322, F1000-AK1332

No

F1000-AK1414, F1000-AK1424, F1000-AK1434, F1000-AK1514, F1000-AK1524, F1000-AK1534, F1000-AK1614

Yes

F1000-AK108, F1000-AK109, F1000-AK110, F1000-AK115, F1000-AK120, F1000-AK125, F1000-AK710

Yes

F1000-AK130, F1000-AK135, F1000-AK140, F1000-AK145, F1000-AK150, F1000-AK155, F1000-AK160, F1000-AK165, F1000-AK170, F1000-AK175, F1000-AK180, F1000-AK185, F1000-GM-AK370, F1000-GM-AK380, F1000-AK711

No

LSU3FWCEA0, LSUM1FWCEAB0, LSX1FWCEA1

No

LSXM1FWDF1, LSUM1FWDEC0, IM-NGFWX-IV, LSQM1FWDSC0, LSWM1FWD0, LSPM6FWD, LSQM2FWDSC0

Yes

vFW1000, vFW2000

Yes

per-packet: Specifies the packet-based forwarding. The device forwards packets in sequence to different CPUs, even though they are the same flow. This policy does not ensure packet order.

Usage guidelines

If you do not specify any keyword for flow identification, the device identifies a flow by source IP address, destination IP address, source port number, destination port number, and protocol number.

Examples

# Specify the three-tuple flow-based policy.

<Sysname> system-view

[Sysname] forwarding policy per-flow three-tuple

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网