Configuring ACL-Based Fixed Rate Limiting Using Traffic Policies
Use the procedure in this section to configure ACL-based fixed rate limiting.
Note: Before configuring this feature, see what to consider in “Configuration notes and
feature limitations for traffic policies.”
- Enter global configuration mode.
- Create a traffic policy and set parameters.
Create a policy that drops packets or bytes that exceed the CIR (committed information rate) limit. The following examples use a packet-based fixed CIR.
device(config)# traffic-policy TPDF1 rate-limit packet-based fixed cir 10000 exceed-action drop count
Create a policy that permits packets or bytes that exceed the CIR limit.
device(config)# traffic-policy TPDF1 rate-limit packet-based fixed cir 10000 exceed-action permit-at-low-pri count
The command sets the fragment threshold at 10,000 packets per second. If the port receives more than 10,000 packets in a one-second interval, the device takes the specified action. If the port receives additional bits during a given one-second interval, the port either drops all packets on the port until the next one-second interval starts or permits packets that exceed the limit.Use the keyword byte-based if you want to specify a CIR based on byte count rather than a packet count. - Create an extended ACL entry or modify an existing extended ACL entry that references the traffic policy.
- Bind the ACL to an interface.
- Enter interface configuration mode.
- Bind the ACL to the interface.
- Exit interface configuration mode.
These commands allow port 1/1/5 to receive a maximum traffic rate of 100 kbps. If the port receives additional bits during a given one-second interval, the port drops the additional inbound packets that are received within that one-second interval.The software allows you to add a reference to a non-existent TPD in an ACL statement and to bind that ACL to an interface. The software does not issue a warning or error message for non-existent TPDs.
- Verify the configuration.
- View the ACL and rate limit counters.
device(config)# show access-list accounting ethernet 1/1/5 in MAC Filters Accounting Information 0: DA ANY SA 0000.0000.0001 - MASK FFFF.FFFF.FFFF action to take : DENY Hit Count: (1Min) 0 (5Sec) 0 (PktCnt) 0 (ByteCnt) 0 -------------------------------------------------------------- 65535: Implicit Rule deny any any Hit Count: (1Min) 5028 (5Sec) 2129 (PktCnt) 5028 (ByteCnt) 643584 -------------------------------------------------------------- - Clear the ACL and rate limit counters.
- Configure DSCP marking and 802.1p priority marking traffic policies.
device(config)#ip access-list ip3 device(config-ext-ipacl-ip3)# sequence 9 permit ip any any dscp-marching 48 dscp-marking 46 traffic-policy VOIP device(config-ext-ipacl-ip3)# sequence 10 permit ip any any dscp-matching 48 dscp-marking 46 802.1p-and-internal-marking 2 traffic-policy VOIP device(config-ext-ipacl-ip3)# sequence 11 permit ip any any dscp-marking 0 traffic-policy VOIP device(config-ext-ipacl-ip3)# sequence 1 permit ip any any 802.1p-priority-matching 5 802.1p-priority-marking 6 internal-priority-marking 3 traffic-policy VOIP device(config-ext-ipacl-ip3)#sequence 3 permit ip any any internal-priority-marking 4 traffic-policy VOIP
ACL-Based Fixed Rate Limiting Using Traffic Policies Configuration Example
device# configure terminal device(config)# traffic-policy TPDF1 rate-limit fixed packet-based cir 10000 exceed-action drop device(config)# ip access-list extended 101 device(config-ext-ipacl-101)# permit ip host 10.10.12.2 any traffic-policy TPDF1 device(config-ext-ipacl-101)# interface ethernet 1/1/5 device(config-if-e1000-1/1/5)# ip access-group 101 in device(config-if-e1000-1/1/5)# exit device(config)# show traffic-policy TPDF1 device(config)# clear access-list accounting all device(config)# clear statistics traffic-policy TPDF1 device(config)#ip access-list ip3 device(config-ext-ipacl-ip3)# sequence 9 permit ip any any dscp-marching 48 dscp-marking 46 traffic-policy VOIP device(config-ext-ipacl-ip3)# sequence 10 permit ip any any dscp-matching 48 dscp-marking 46 802.1p-and-internal-marking 2 traffic-policy VOIP device(config-ext-ipacl-ip3)# sequence 11 permit ip any any dscp-marking 0 traffic-policy VOIP device(config-ext-ipacl-ip3)# sequence 1 permit ip any any 802.1p-priority-matching 5 802.1p-priority-marking 6 internal-priority-marking 3 traffic-policy VOIP device(config-ext-ipacl-ip3)# sequence 3 permit ip any any internal-priority-marking 4 traffic-policy VOIP device(config-ext-ipacl-ip3)# exit