Configure Priority Flow Control Safely with dcb pfc
You will finish with a small, repeatable workflow for inspecting and changing Priority-based Flow Control (PFC) on a Linux network device. The examples use dcb from iproute2 6.1.0. PFC changes link behaviour, so use a maintenance window and confirm the device name before setting anything.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes for a read-only check, or longer if you need to coordinate a live network change. You need iproute2, a device whose driver exposes the Linux DCB interface, and elevated privileges for changes. Reading settings is usually harmless, but the kernel or driver may still reject a request.
1. Confirm the installed tool
Start with ordinary, read-only checks. They confirm which binary and iproute2 release will interpret the commands:
$ command -v dcb
/usr/sbin/dcb
$ dcb -V
dcb utility, iproute2-6.1.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4
The installed package is relevant here. Syntax and supported attributes can vary between iproute2 releases and between network drivers. This guide follows the local dcb-pfc(8) and dcb(8) documentation.
Checkpoint
If dcb -V is unavailable, stop and install or repair iproute2 through your normal system-management process. Do not copy examples from a different host and assume that its attributes exist here.
2. Check whether the device exposes PFC
Replace INTERFACE with the exact device name. This query does not change configuration:
$ sudo dcb pfc show dev INTERFACE
pfc-cap 8 macsec-bypass off delay 0
prio-pfc 0:off 1:off 2:off 3:off 4:off 5:off 6:off 7:off
The output is device-specific. pfc-cap is read-only and reports how many traffic classes can support PFC simultaneously. prio-pfc reports the enabled state for priorities 0 through 7. The example output is illustrative of a device with eight available classes, not a guaranteed default.
If you see Attribute read: Operation not supported, the device or its driver is not exposing the requested DCB attribute. Check the interface name with ip link, then consult the driver documentation. Do not treat a rejected read as proof that PFC is safely disabled.
For a narrower read, name the fields you need:
$ sudo dcb pfc show dev INTERFACE pfc-cap prio-pfc delay
pfc-cap 8 delay 0
prio-pfc 0:off 1:off 2:off 3:off 4:off 5:off 6:off 7:off
3. Record the current state before changing it
Save the complete output in your change record. You will need the old values if the link behaves badly or the change must be reversed:
$ sudo dcb pfc show dev INTERFACE | tee pfc-before.txt
The file is ordinary local output, so choose a directory with suitable permissions if the host is shared. Check that it contains the expected device state before continuing:
$ sed -n '1,5p' pfc-before.txt
pfc-cap 8 macsec-bypass off delay 0
prio-pfc 0:off 1:off 2:off 3:off 4:off 5:off 6:off 7:off
There is no transaction or automatic rollback around dcb pfc set. Keeping this record is the practical undo mechanism. If another administrator changes the device between the read and the write, re-read it rather than overwriting their work.
4. Enable only the priorities you require
Use the writable prio-pfc array to enable priorities 6 and 7 while retaining the other current values:
$ sudo dcb pfc set dev INTERFACE prio-pfc 6:on 7:on
Array entries use priority:value. The entries are processed from left to right, and entries you omit are queried from the kernel and retained. That makes this form suitable for a targeted change. It does not configure the switch, peer or traffic classification for you; all parts of a PFC design must agree.
Verify the result immediately:
$ sudo dcb pfc show dev INTERFACE prio-pfc
prio-pfc 0:off 1:off 2:off 3:off 4:off 5:off 6:on 7:on
If the command fails, inspect its exit status and query the device again. A non-zero status means the command failed. Do not assume that a partially displayed or cached value was applied.
5. Set every priority deliberately when needed
To establish a known policy, use the special all key first, then override the exceptions. This example turns PFC off for every priority except 6 and 7 and sets the propagation-delay allowance to hexadecimal 0x1000, which is 4096 bits:
$ sudo dcb pfc set dev INTERFACE \
prio-pfc all:off 6:on 7:on \
delay 0x1000
The later entries win, so the order matters. The valid priority range is 0 to 7. The delay value must be in the range 0 to 65535 and represents an allowance for round-trip link propagation delay in bits. It is not a time in milliseconds.
Use decimal output to make the applied value easy to compare with the command:
$ sudo dcb pfc show dev INTERFACE prio-pfc delay
prio-pfc 0:off 1:off 2:off 3:off 4:off 5:off 6:on 7:on
delay 4096
Warning
Changing PFC can alter congestion and loss behaviour immediately. An incorrect lossless-priority design can cause pause propagation or make applications fail in less obvious ways. If the new state is wrong, restore the recorded values with another explicit set command. For example, if the previous policy had PFC disabled everywhere and a zero delay:
$ sudo dcb pfc set dev INTERFACE prio-pfc all:off delay 0
$ sudo dcb pfc show dev INTERFACE prio-pfc delay
6. Check MACsec bypass separately
macsec-bypass is a separate writable attribute. It describes whether the sending station can bypass MACsec processing when MACsec is disabled:
$ sudo dcb pfc show dev INTERFACE macsec-bypass
macsec-bypass off
$ sudo dcb pfc set dev INTERFACE macsec-bypass on
$ sudo dcb pfc show dev INTERFACE macsec-bypass
macsec-bypass on
Only change this when it matches the host's MACsec design and driver support. It is not a general performance switch. Restore off with sudo dcb pfc set dev INTERFACE macsec-bypass off if the setting was accidental.
7. Read PFC counters when diagnosing traffic
The request and indication counters are not included in ordinary output. Ask for them explicitly, or use -s to include statistics:
$ sudo dcb -s pfc show dev INTERFACE
pfc-cap 8 macsec-bypass off delay 4096
prio-pfc 0:off 1:off 2:off 3:off 4:off 5:off 6:on 7:on
requests 0:0 1:0 2:0 3:0 4:0 5:0 6:12 7:8
indications 0:0 1:0 2:0 3:0 4:0 5:0 6:4 7:3
Counter names and values describe sent and received PFC frames per traffic class. They are evidence about observed traffic, not proof that the whole end-to-end configuration is correct. The exact values and even counter support depend on the device.
Done means
dcb -Videntifies the iproute2 release you used.- The target interface was checked and its PFC state was recorded first.
- Only the intended priorities, delay and MACsec setting were changed.
- A post-change
dcb pfc showconfirms the effective state. - You know the explicit command that restores the recorded configuration.
- Statistics were checked when diagnosing PFC traffic, without treating counters as a complete network test.