Configuring Fixed Rate Limiting on the CPU
To apply fixed rate limiting on the CPU, you must complete the following actions:
- Create a traffic policy.
- Create an ACL containing the traffic policy, or add a statement containing the traffic policy to an existing ACL.
- Bind the ACL containing the policy to the CPU.
Perform the following steps to bind the ACL containing the policy to the CPU.
- Enter global configuration mode.
- Enter CPU configuration mode. The active keyword used in the command designates the active controller of a stack but is also used for a standalone unit, whether or not stacking is enabled.
- Bind the ACL that was previously created with the desired traffic policy to the CPU.
The previous example binds an IPv6 ACL (ipv6_icmp) to the CPU interface and applies the ACL to incoming traffic.
- (Optional) Enter the
show running-config interface cpu activecommand to verify that the ACL has been applied. - When you are finished, exit CPU configuration mode.
The following example creates a traffic policy, adds it to an ACL (cpu_ipv4), applies the ACL to the CPU interface, and verifies the configuration.
device# configure terminal device(config)# traffic-policy TPDF1 rate-limit packet-based fixed cir 10000 exceed-action drop device(config)# ip access-list extended cpu_ipv4 device(config-ext-ipacl-cpu_ipv4)# permit ip host 10.10.12.2 any traffic-policy TPDF1 device(config-ext-ipacl-cpu_ipv4)# interface cpu active device(config-if-cpu-active)# ip access-group cpu_ipv4 in device(config-if-cpu-active)# show running-config interface cpu active interface cpu active ip access-group cpu_ipv4 in device(config-if-cpu-active)# exit device(config)#