SR OS routers support an extensive set of configurable mechanisms to protect the CPU from being flooded with control or management traffic.
These protection mechanisms are a set of configurable hardware-based filters, classification, queuing, and rate-limiting functions that drop unwanted traffic before it reaches the control processor.
ACLs filters: IPv4, IPv6, and MAC
anti-spoofing, uRPF
distributed CPU protection
CPM Filters: IPv4, IPv6, and MAC
centralized CPU Protection
per-peer queues, protocol queues, CPM queues
Out-band and in-band traffic: Management access filters