Configuring fixed rate limiting on the CPU

To apply fixed rate limiting on the CPU:

  • Create a traffic policy.
  • Create an ACL containing the traffic policy, or add a statement containing the traffic policy to an existing ACL.
  • Bind the ACL containing the policy to the CPU as shown in the following procedure.

  1. Enter global configuration mode.
    device# configure terminal
    device(config)#
    
  2. Enter CPU configuration sub-mode.
    device(config)# interface cpu unit active
    device(config-if-cpu-active)# 
    
    The keyword active used in the command designates the active controller of a stack but is also used for a standalone unit, whether or not stacking is enabled.
  3. Bind the ACL that was previously created with the desired traffic policy to the CPU.
    device(config-if-cpu-active)# ipv6 access-group ipv6_icmp in
    
    The previous example binds an IPv6 ACL (ipv6_icmp) to the CPU interface and applies the ACL to incoming traffic.
    Note: IPv4 extended ACLs and IPv6 ACLs can be applied to the CPU interface. Use the ip access-group command followed by the keyword in to apply an IPv4 ACL as shown in the following example.
    device# configure terminal
    device(config)# interface cpu unit active
    device(config-if-cpu-active)# ip access-group block_telnet in
    device(config-if-cpu-active)# exit
    
    The previous example binds an existing extended IPv4 ACL (block_telnet) to the CPU interface.
  4. When you are finished, exit CPU configuration submode.
    device(config-if-cpu-active)# exit
    device(config)#
    

The following example creates a traffic policy, adds it to an ACL (cpu_ipv4), applies the ACL to the CPU interface, and verifies the configuration.

SMEs to provide helpful examples once design is confirmed for the release. An example rate limiting DHCP packets will be included.

device# configure terminal
device(config)# traffic-policy TPDF1 rate-limit packet-based fixed cir 10000 exceed-action drop
device(config)# ip access-list extended cpu_ipv4 
device(config-ext-ipacl-cpu_ipv4)# permit ip host 10.10.12.2 any traffic-policy TPDF1
device(config-ext-ipacl-cpu_ipv4)# interface cpu unit active
device(config-if-cpu-active)# ip access-group cpu_ipv4 in
device(config-if-cpu-active)# show running-config interface cpu active
interface cpu active
ip access-group cpu_ipv4 in
device(config-if-cpu-active)# exit
device(config)#