Configuring ACL-Based Adaptive Rate Limiting Using Traffic Policies

You can configure adaptive rate limiting to forward traffic, modify the IP precedence of and then forward traffic, or drop traffic based on whether the traffic is within the limit or exceeds the set limit.

These commands:

  • Set the maximum number of traffic policies.
  • Create an adaptive traffic policy that enables ACL statistics (counting).
  • Create a new extended ACL entry and bind the ACL to an interface.
  • Verify the configuration.

  1. Enter global configuration mode.
    device# configure terminal
    
  2. Create traffic policies and set parameters.
    1. Create a policy, TPDrop, that drops packets that exceed the limit.
      device(config)# traffic-policy TPDrop rate-limit adaptive cir 10000 cbs 1600 pir 20000 pbs 4000 exceed-action drop count
      
    2. Create a policy, TPallow, that permits packets that exceed the limit.
      device(config)# traffic-policy TPallow rate-limit adaptive cir 10000 cbs 1600 pir 20000 pbs 4000 exceed-action permit-at-low-pri count
      
    The command sets the fragment threshold at 10,000 packets per second. If the port receives more than 10,000 packets in a one-second interval, the device takes the specified action. If the port receives additional bits during a given one-second interval, the port either drops all packets on the port until the next one-second interval starts or permits packets that exceed the limit.
  3. Verify the traffic policy configuration.
    device(config)# show traffic-policy 
    Traffic Policy - TPallow:
    
            Metering Enabled, Parameters:
                    Mode: Adaptive Rate-Limiting
                    cir: 400000 kbps,    cbs: 125000 kbits,    pir: 12000000 kbps,    pbs: 1250000000 kbits
    
            Counting Enabled
            Number of References/Bindings: 1
    Traffic Policy - TPDrop:
    
            Metering Enabled, Parameters:
                    Mode: Adaptive Rate-Limiting
                    cir: 10000 kbps,    cbs: 1600 kbits,    pir: 20000 kbps,    pbs: 4000 kbits
    
            Counting Enabled
            Number of References/Bindings: 0
    
  4. Create appropriate ACL entries.
    1. Create a new extended IPv4 ACL or modify an existing extended IPv4 ACL that references the traffic policy.
      device(config)# ip access-list extended 104 
      device(config-ext-ipacl-104)# permit ip host 1.1.1.2 any traffic-policy TPallow
      device(config-ext-ipacl-104)# exit
      
      The previous example creates an IPv4 extended ACL that allows traffic from the specified IP host and applies the traffic policy created earlier to allow traffic at a low priority.
    2. Create or modify an IPv6 ACL that references the traffic policy.
      device(config)# ipv6 access-list acl105 
      device(config-ipv6-access-list acl105)# permit ip any any 802.1p-priority matching 3 traffic-policy TPdrop
      device(config-ipv6-access-list acl105)# exit
      
      The previous example creates an IPv6 ACL that permits an IP traffic, and if it matches IEEE 802.1p priority 3, it applies the traffic policy TPdrop, created earlier to drop and count traffic that exceed the defined rate limit.
  5. Verify the ACLs.
    device(config)# show access-list all
    ...
    
    
    Extended IP access list 104 : 1 entry
    permit ip host 1.1.1.2 any traffic-policy TPallow
    
    Extended IP access list 105 : 1 entry
    permit ip any any 802.1p-priority-matching 3 traffic-policy TPdrop
    ...
    
  6. Bind the ACL to an interface.
    1. Enter interface configuration mode.
      device(config)# interface ethernet 1/1/6
      
    2. Bind the ACL to the interface.
      device(config-if-e1000-1/1/6)# ip access-group 104 in
      device(config-if-e1000-1/1/6)# exit
      
      device(config-if-e1000-1/1/6)# ipv6 access-group acl105 in
      device(config-if-e1000-1/1/6)# exit
      
  7. Clear the ACL and rate limit counters.
    1. Clear the ACL counters.
      device(config)# clear access-list accounting all
      Traffic Policy TPallow: cleared
      
    2. Clear the rate limit counters.
      device(config)# clear statistics traffic-policy TPallow
      device(config)# clear statistics traffic-policy TPdrop 
      
  8. Configure DSCP marking and IEEE 802.1p priority marking traffic policies.
    device (config)# ipv6 access-list ipv6
    device(config-ipv6acl-ipv6)# sequence 2 permit ipv6 any any dscp-matching 48 dscp-marking 62 internal-priority-marking 7
    device(config-ipv6acl-ipv6)# sequence 3 permit ipv6 any any dscp-matching 48 dscp-marking 62 802.1p-priority-marking 4 internal-priority-marking 4
    device(config-ipv6acl-ipv6)# sequence 8 permit ipv6 any any dscp-marking 0

ACL-Based Adaptive Rate Limiting Using Traffic Policies Configuration Example

device# configure terminal
device(config)# traffic-policy TPDrop rate-limit adaptive cir 10000 cbs 1600 pir 20000 pbs 4000 exceed-action drop count
device(config)# traffic-policy TPallow rate-limit adaptive cir 10000 cbs 1600 pir 20000 pbs 4000 exceed-action permit-at-low-pri count
device(config)# show traffic-policy
!
device(config)# ip access-list extended 104 
device(config-ext-ipacl-104)# permit ip host 1.1.1.2 any traffic-policy TPallow
device(config-ext-ipacl-104)# exit
device(config)# ipv6 access-list acl105 
device(config-ipv6-access-list acl105)# permit ip any any 802.1p-priority matching 3 traffic-policy TPdrop
device(config-ipv6-access-list acl105)# exit
device(config)# show access-list all
device(config)# interface ethernet 1/1/6
device(config-if-e1000-1/1/6)# ip access-group 104 in
device(config-if-e1000-1/1/6)# ipv6 access-group acl105 in
device(config-if-e1000-1/1/6)# exit
device(config)# clear access-list accounting all
device(config)# clear statistics traffic-policy TPDA4 
device (config)# ipv6 access-list ipv6
device(config-ipv6acl-ipv6)# sequence 2 permit ipv6 any any dscp-matching 48 dscp-marking 62 internal-priority-marking 7
device(config-ipv6acl-ipv6)# sequence 3 permit ipv6 any any dscp-matching 48 dscp-marking 62 802.1p-priority-marking 4 internal-priority-marking 4
device(config-ipv6acl-ipv6)# sequence 8 permit ipv6 any any dscp-marking 0