Configuring fixed rate limiting on the CPU
- Enter global configuration mode.
- Enter CPU configuration sub-mode.
The keyword active used in the command designates the active controller of a stack but is also used for a standalone unit, whether or not stacking is enabled.
- Bind the ACL that was previously created with the desired traffic policy to the CPU.
The previous example binds an IPv6 ACL (ipv6_icmp) to the CPU interface and applies the ACL to incoming traffic.
device# configure terminal device(config)# interface cpu unit active device(config-if-cpu-active)# ip access-group block_telnet in device(config-if-cpu-active)# exit
The previous example binds an existing extended IPv4 ACL (block_telnet) to the CPU interface. - When you are finished, exit CPU configuration submode.
The following example creates a traffic policy, adds it to an ACL (cpu_ipv4), applies the ACL to the CPU interface, and verifies the configuration.
SMEs to provide helpful examples once design is confirmed for the release. An example
rate limiting DHCP packets will be included.
device# configure terminal device(config)# traffic-policy TPDF1 rate-limit packet-based fixed cir 10000 exceed-action drop device(config)# ip access-list extended cpu_ipv4 device(config-ext-ipacl-cpu_ipv4)# permit ip host 10.10.12.2 any traffic-policy TPDF1 device(config-ext-ipacl-cpu_ipv4)# interface cpu unit active device(config-if-cpu-active)# ip access-group cpu_ipv4 in device(config-if-cpu-active)# show running-config interface cpu active interface cpu active ip access-group cpu_ipv4 in device(config-if-cpu-active)# exit device(config)#