Traffic policies for ACL-based rate limit restrictions and limitations
When you apply a traffic policy to an interface, you do so by adding a reference to the traffic policy in an ACL entry, instead of applying the individual traffic policy to the interface. The traffic policy becomes an active traffic policy or active TPD when you bind its associated ACL to an interface.
Note the following when configuring traffic policies:
- A traffic policy with the action permit-as-low-pri is not supported on PE ports in a Campus Fabric (SPX) network.
- The maximum number of supported active TPDs is a system-wide parameter and depends on the device you are configuring. The total number of active TPDs cannot exceed the system maximum. Refer to “Maximum number of traffic policies supported on a device.”
- You can reference the same traffic policy in more than one ACL entry within an ACL. For example, two or more ACL statements in ACL 101 can reference a TPD named TPD1.
- You can reference the same traffic policy in more than one ACL. For example, ACLs 101 and 102 could both reference a TPD named TPD1.
- Rate limits and ACL counting are applied at the traffic policy level and are cumulative across ACLs and ACL entries on which they are applied. However, they are not cumulative across port regions.
- To modify or delete an active traffic policy, you must first unbind the ACL that references the traffic policy.
- When you define a TPD (when you enter the
traffic-policycommand), explicit marking of CoS parameters, such as traffic class and 802.1p priority, are not available on the device. In the case of a TPD defining rate limiting, the device re-marks CoS parameters based on the DSCP value in the packet header and the determined conformance level of the rate limited traffic as shown in the following table.CoS parameters for packets that use rate limiting traffic policies
- When you define a TPD, reference the TPD in an ACL entry and then apply the ACL to
a VLAN or VLAN interfaces, the rate limit policy is cumulative for all of the ports
in the port region. If the VLAN contains ports that are in different port regions,
the rate limit policy is applied per port region.
For example, TPD1 has a rate limit policy of 600M and is referenced in ACL 101. ACL 101 is applied to VLAN 100, which contains Ethernet ports 1/1/1 to 1/1/4. Because Ethernet ports 1/1/1 and 1/1/2 are in a different port region from ports 1/1/3 and 1/1/4, the rate limit policy will be 600M for ports 1/1/1 and 1/1/2 and 600M for ports 1/1/3 and 1/1/4.
Maximum number of traffic policies supported on a device
The maximum number of supported active traffic policies is a system-wide parameter that depends on the device you are configuring, as follows:
- By default, up to 1024 active traffic policies are supported on Layer 2 switches. This value is fixed on Layer 2 switches and cannot be modified.
- For FastIron devices the number of active traffic policies supported on Layer 3 switches varies depending on the configuration and the available system memory. The default value and also the maximum number of traffic policies supported on Layer 3 switches is 50.