# Cisco Storm-Control Configuration

**URL:** https://forum.networklessons.com/t/cisco-storm-control-configuration/1163
**Category:** Lessons Discussion
**Created:** [December 27, 2016, 5:45pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163 "2016-12-27T17:45:28Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 27, 2016, 5:45pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/1 "2016-12-27T17:45:28Z")

</div>

This topic is to discuss the following lesson:

[https://networklessons.com/cisco/ccie-enterprise-infrastructurecisco-storm-control-configuration/](https://networklessons.com/cisco/ccie-enterprise-infrastructurecisco-storm-control-configuration/)

---

<div class="post-metadata">

### Author: ![johnfrades](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/j/e0b2c6/32.png) [@johnfrades](https://forum.networklessons.com/u/johnfrades)
#### Post date: [October 15, 2015, 2:22am UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/2 "2015-10-15T02:22:29Z")

</div>

question, on the last sentence you said the default action is exceeding traffic will be dropped. but you can also use to shutdown the interface or send a trap.

if you configure to send a trap, the exceeding traffic will not be dropped? just only to inform you that it exceeds?

because on the selection of action, its only “Shutdown” and “Trap”. theres no “Drop the exceeding traffic”.

or it works this way that, it will drop the exceeding traffic, you just need to choose the 2nd option on what to do with it? is it you’ll shutdown the interface or send a trap?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [October 16, 2015, 4:16pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/3 "2015-10-16T16:16:28Z")

</div>

Hi John,

In both cases, the exceeding traffic will be dropped. The only difference is the “extra” action that we perform. Do you want to shut the interface or only send a SNMP trap? That’s it.

Rene

---

<div class="post-metadata">

### Author: ![linuxdancer](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/linuxdancer/32/469_2.png) [@linuxdancer](https://forum.networklessons.com/u/linuxdancer)
#### Post date: [June 30, 2016, 10:42pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/4 "2016-06-30T22:42:48Z")

</div>

Hey Rene,

Just wondering. Is it better to program both sides of a trunk for storm control? It seems to me that one side of the link is good enough. Also I assume that it’s OK to assign this to a port-channel? When I do so I notice that it writes the storm control parameters to both the trunk and port channel which I would expect.

Thanks

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 1, 2016, 4:27pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/5 "2016-07-01T16:27:13Z")

</div>

Hi Michael,

I guess this depends on which end of the trunk you expect to have a broadcast storm 🙂 There’s no harm configuring this on both (or all) your switches. Configuring this on an etherchannel is no problem. Make sure you do this on the logical interface, not one of the member physical interfaces or it will be suspended.

Rene

---

<div class="post-metadata">

### Author: ![ryan.mills1](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/ad7895/32.png) [@ryan.mills1](https://forum.networklessons.com/u/ryan.mills1)
#### Post date: [August 28, 2016, 3:33pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/6 "2016-08-28T15:33:43Z")

</div>

Anyone know a good tool on Windows/Linux to generate a Broadcast, Unicast and Multicast Storm?  
Would be great to test this on my switches.

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [August 29, 2016, 11:32am UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/7 "2016-08-29T11:32:18Z")

</div>

Hi Ryan,

You could try [Ostinato](http://ostinato.org/).

Rene

---

<div class="post-metadata">

### Author: ![unitynetworks](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/u/9f8e36/32.png) [@unitynetworks](https://forum.networklessons.com/u/unitynetworks)
#### Post date: [November 14, 2016, 8:31pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/8 "2016-11-14T20:31:08Z")

</div>

Hi Rene

I was packet sniffing a server switch port where remote users to this server have experienced very slow responses to http requests, on one occasion when I was sniffing the server switch port the Http responses (HTTP/1.1 200 OK) started to increase to over 30 secs on occasions, I did notice a high amount of broadcasts and multicasts with 62% of frames on the sniffer trace (13 mins duration) was either a broadcast or multicast. I want to insert a broadcast/unicast storm control is there a rule of thumb to configure a percentage level of broadcasts/ multicast prior to them being dropped??

Also do you have a service to analyse wireshark sniffer traces I would like a second opinion on my sniffer findings.

Many Thanks

Simon

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [November 22, 2016, 4:59pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/9 "2016-11-22T16:59:51Z")

</div>

Hi Simon,

Before you implement storm-control, I would start by taking a closer look at the broadcast/multicast traffic that you captured. 62% is a lot so you might want to make sure nothing strange is going on.

Anywhere above 10-20% is considered high.

Storm-control might work but it’s more of a band-aid solution 🙂

I don’t offer any wireshark analysis. Not that I don’t want to but any 1-on-1 work is very time consuming.

Rene

---

<div class="post-metadata">

### Author: ![Zaman.rubd](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/z/45deac/32.png) [@Zaman.rubd](https://forum.networklessons.com/u/Zaman.rubd)
#### Post date: [February 8, 2017, 2:12pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/10 "2017-02-08T14:12:01Z")

</div>

Hi Rene,  
Great Article 🙂  
What is the meaning of the sentence “default action will drop exceeding traffic”. Exceeding traffic means exceeding Broadcast/Multicast/Unknown Unicast traffic will be drop ?? and regular traffic will not, right ?? Thanks

br/zaman

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [February 10, 2017, 1:19pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/11 "2017-02-10T13:19:50Z")

</div>

That’s right, for example if you configure:

`SwitchA(config-if)#storm-control broadcast level 30`

Then broadcast traffic above 30% will be dropped, that’s it.

---

<div class="post-metadata">

### Author: ![chrisnewnham17](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/c/f9ae1b/32.png) [@chrisnewnham17](https://forum.networklessons.com/u/chrisnewnham17)
#### Post date: [November 4, 2017, 6:54pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/12 "2017-11-04T18:54:52Z")

</div>

Can you explain exactly what the Unicast element is? What makes a unicast “unknown”? 🙂

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [November 6, 2017, 7:01am UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/13 "2017-11-06T07:01:36Z")

</div>

Hello Chris

Unknown unicast traffic is essentially unicast traffic for which a switch does not have the destination MAC address already in its CAM table. Such traffic will require flooding from all of its ports thus adding to the severity of a potential broadcast storm.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 23, 2019, 1:36pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/14 "2019-12-23T13:36:53Z")

</div>

A post was merged into an existing topic: [Unicast Flooding due to Asymmetric Routing](https://forum.networklessons.com/t/unicast-flooding-due-to-asymmetric-routing/1272/36)

---

<div class="post-metadata">

### Author: ![ratha.chum9](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/da6949/32.png) [@ratha.chum9](https://forum.networklessons.com/u/ratha.chum9)
#### Post date: [March 26, 2022, 12:22am UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/15 "2022-03-26T00:22:09Z")

</div>

Where is the best place to apply storm-control?  
Interface facing to users’ PC?  
Interface trunk up link from switch to other switch?  
Should I apply to switch for server farm?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [March 29, 2022, 6:27am UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/16 "2022-03-29T06:27:03Z")

</div>

Hello Ratha

Storm control should be applied on any interface that has the potential to receive any kind of packet storm. Here are some guidelines to keep in mind:

1. In general, it’s always best to apply it as close as possible to the source of the storm. That may mean applying it on interfaces facing user PCs, although there is minimal risk of a storm from a single device.
2. This is a feature that is often applied after a broadcast storm is detected, however, it may be good practice to apply it proactively to mitigate against the possibility of a storm in the future.
3. When applied proactively, care should be taken to set the thresholds as they may begin to block legitimate traffic.
4. Storm control should be applied in situations where there is heavy use of multicast.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![davidvfoo](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/d/22d042/32.png) [@davidvfoo](https://forum.networklessons.com/u/davidvfoo)
#### Post date: [September 7, 2022, 11:16pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/17 "2022-09-07T23:16:39Z")

</div>

> [@ReneMolenaar](#):
>
> shut the interface or only send a SNMP trap

Am I correct to say that you can also shut the interface AND send a SNMP trap.

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [September 12, 2022, 11:40am UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/18 "2022-09-12T11:40:54Z")

</div>

Hello David

Unfortunately, I don’t have a switch readily available that supports storm control, so I am unable to try this out. The CML switch I have available doesn’t support it. However, looking at related [Cisco documentation](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/15-1/XE_330SG/configuration/guide/config/bcastsup.pdf), the command is described as follows:

`Switch(config-if)# storm-control action {shutdown | trap}`

This syntax seems to indicate that either the interface will go into error-disable state, OR an SNMP trap will be generated. Both options cannot be configured simultaneously using this command.

However, if you want to be able to do both, you should be able to set the `shutdown` option and then configure SNMP traps for the state of interfaces independently as shown in the following lesson:

[https://networklessons.com/cisco/ccie-enterprise-infrastructurehow-to-configure-snmpv2-on-cisco-ios-router](https://networklessons.com/cisco/ccie-enterprise-infrastructurehow-to-configure-snmpv2-on-cisco-ios-router)

Just to be clear, I have not tested this, but it could be a good exercise to try out to confirm this functionality.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![rips.naik1990](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/87869e/32.png) [@rips.naik1990](https://forum.networklessons.com/u/rips.naik1990)
#### Post date: [May 21, 2023, 7:34pm UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/19 "2023-05-21T19:34:57Z")

</div>

Can we use this to control bandwidth usage of the end devices which is consuming too much bandwidth creating performance issues for others in the environment where there is no QoS ?  
Also what other techniques can we use to control broadcast optional to storm control in general ?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [May 23, 2023, 5:58am UTC](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163/20 "2023-05-23T05:58:00Z")

</div>

Hello Ripal

> [@rips.naik1990](#):
>
> Can we use this to control bandwidth usage of the end devices which is consuming too much bandwidth creating performance issues for others in the environment where there is no QoS ?

Storm control can only be applied to [broadcast](https://notes.networklessons.com/broadcast-traffic), [multicast](https://notes.networklessons.com/multicast) and [unknown unicast traffic](https://notes.networklessons.com/unknown-unicast-traffic). It does not affect [normal unicast traffic](https://notes.networklessons.com/unicast-traffic). So this feature cannot be used to control the general bandwidth usage of end devices.

> [@rips.naik1990](#):
>
> Also what other techniques can we use to control broadcast optional to storm control in general ?

Well, some techniques you can use to specifically control broadcast storms include the use of:

- Access lists
- Using the `rate-limit` command on interfaces, although this falls under QoS

Some other features that indirectly reduce broadcast storms include:

- Spanning tree, which prevents layer 2 loops and the resulting broadcast storm that would ensue
- Making smaller network segments by creating more VLANs
- Pruning unnecessary VLANs
- implementing IGMP snooping for multicast environments

I hope this has been helpful!

Laz

[Next page](https://forum.networklessons.com/t/cisco-storm-control-configuration/1163.md?page=2)
