Without more information my guess is that changing the routes in the hardware tables goes wrong or takes a long time. During that time traffic is send to the CPU for forwarding instead of through hardware and is causing the CPU to become too busy.Ano...
yes., but as you can assign vlans through the policy itself (pvid) you don't need VSA 211. Checkout table 114 in the userguide for vsa's supported with OnePolicy enabled. Table 114: Supported Access-Accept Attributes for ONEPolicy
Have you enabled policy (I assume so as you have dynamic authorization enabled) ?If so, then EXOS does not honor VSA211, only the attributes mentioned in the userguide for policy and only if you enable maptable response both and vlanauthorization.