Configuring Fixed Rate Limiting on the CPU

To apply fixed rate limiting on the CPU, you must complete the following actions:

  • Create a traffic policy.
  • Create an ACL containing the traffic policy, or add a statement containing the traffic policy to an existing ACL.
  • Bind the ACL containing the policy to the CPU.

Perform the following steps to bind the ACL containing the policy to the CPU.

  1. Enter global configuration mode.
    device# configure terminal
    device(config)#
    
  2. Enter CPU configuration mode.
    device(config)# interface cpu active
    device(config-if-cpu-active)# 
    
    The active keyword used in the command designates the active controller of a stack but is also used for a standalone unit, whether or not stacking is enabled.
  3. Bind the ACL that was previously created with the desired traffic policy to the CPU.
    device(config-if-cpu-active)# ipv6 access-group ipv6_icmp in
    
    The previous example binds an IPv6 ACL (ipv6_icmp) to the CPU interface and applies the ACL to incoming traffic.
    Note: IPv4 extended ACLs and IPv6 ACLs can be applied to the CPU interface. Use the ip access-group command followed by the in keyword to apply an IPv4 ACL. The following example binds an existing IPv4 extended ACL (block_telnet) to the CPU interface.
    device# configure terminal
    device(config)# interface cpu active
    device(config-if-cpu-active)# ip access-group block_telnet in
    device(config-if-cpu-active)# exit
    
  4. (Optional) Enter the show running-config interface cpu active command to verify that the ACL has been applied.
    device(config-if-cpu-active)# show running-config interface cpu active
    interface cpu active
    ip access-group block_telnet in
  5. When you are finished, exit CPU configuration mode.
    device(config-if-cpu-active)# exit
    device(config)#
    

The following example creates a traffic policy, adds it to an ACL (cpu_ipv4), applies the ACL to the CPU interface, and verifies the configuration.

device# configure terminal
device(config)# traffic-policy TPDF1 rate-limit packet-based fixed cir 10000 exceed-action drop
device(config)# ip access-list extended cpu_ipv4 
device(config-ext-ipacl-cpu_ipv4)# permit ip host 10.10.12.2 any traffic-policy TPDF1
device(config-ext-ipacl-cpu_ipv4)# interface cpu active
device(config-if-cpu-active)# ip access-group cpu_ipv4 in
device(config-if-cpu-active)# show running-config interface cpu active
interface cpu active
ip access-group cpu_ipv4 in
device(config-if-cpu-active)# exit
device(config)#