ACL Based
Policer
The following is a
sample ACL based policer configuration. In this example, the ACL is applied to
a BGP session.
RP/0/RSP1/CPU0:router(config)# ipv4 access-list lpts_acl_1
RP/0/RSP1/CPU0:router(config-ipv4-acl)# 10 permit tcp any host 200.0.0.1
RP/0/RSP1/CPU0:router(config-ipv4-acl)# 20 deny ipv4 any any
RP/0/RSP1/CPU0:router(config-ipv4-acl)# commit
RP/0/RSP1/CPU0:router(config-ipv4-acl)# end
RP/0/RSP1/CPU0:router(config)# lpts pifib hardware police acl lpts_acl_1 rate 1000
RP/0/RSP1/CPU0:router(config)# commit
The following is a
show command and its sample output for the preceding policer configuration:
RP/0/RSP1/CPU0:router# show lpts pifib hardware entry brief location 0/1/cpu0
Node: 0/1/CPU0:
----------------------------------------
L3 - L3 Protocol;L4 - Layer4 Protocol; Intf - Interface;
Dest - Destination Node; V - Virtual;
na - Not Applicable or Not Available;
LU - Local chassis fabric unicast;
LM - Local chassis fabric multicast;
RU - Multi chassis fabric unicast;
RM - Multi chassis fabric multicast;
def - default
Offset L3 VRF id L4 Intf Dest laddr,Port raddr,Port acl name
------ ---- ------------ ------ --------------- --------- ---------- -----------------------------------
8 IPV4 * any any Local any,any any,any
9 CLNS * - any LU(30) - -
10 IPV4 * ICMP any Local any,any any,ECHO
11 IPV4 * OSPF Optimized LM[6] 224.0.0.5,any any,any
12 IPV4 * OSPF Optimized LM[6] 224.0.0.6,any any,any
13 IPV4 * OSPF Optimized LM[6] any,any any,any
14 IPV4 default TCP any LU(30) any,65145 200.0.0.1,179 lpts_acl_1
15 IPV4 default TCP any LU(30) any,179 200.0.0.1,any lpts_acl_1
16 IPV4 default TCP any LU(30) any,23 any,any
17 IPV4 default UDP any LU(30) any,161 any,any
18 IPV4 **nVSatellite UDP any LU(30) any,161 any,any
19 IPV4 default UDP any LU(30) any,162 any,any
20 IPV4 **nVSatellite UDP any LU(30) any,162 any,any
21 IPV4 default L2TPV3 any LU(30) any,any any,any
22 IPV4 * OSPF any LM[2] 224.0.0.5,any any,any
23 IPV4 * OSPF any LM[2] 224.0.0.6,any any,any
24 IPV4 * TCP any LU(30) any,any any,179
25 IPV4 * UDP any LU(30) any,1701 any,any
26 IPV4 * TCP any LU(30) any,179 any,any
27 IPV4 * ICMP any LU(30) any,any any,ECHOREPLY
28 IPV4 * ICMP any Local any,any any,UNREACH
29 IPV4 * ICMP any Local any,any any,TIMXCEED
30 IPV4 * ICMP any Local any,any any,PARAMPROB
31 IPV4 * ICMP any Local any,any any,SRCQUENCH
32 IPV4 * ICMP any Local any,any any,REDIRECT
33 IPV4 * ICMP any Local any,any any,TSTAMP
34 IPV4 * ICMP any Local any,any any,MASKREQ
35 IPV4 * TCP any LU(30) any,any any,any
36 IPV4 * UDP any LU(30) any,any any,any
37 IPV4 * RSVP any Local any,any any,any
38 IPV4 * OSPF any LM[2] any,any any,any
39 IPV4 * any any LU(30) any,any any,any
40 IPV4 * UDP any Local any,any any,any
4 IPV6 * any any Local any,any any,any
5 IPV6 * ICMP6 any Local any,any any,NDRTRSLCT
6 IPV6 * ICMP6 any Local any,any any,NDRTRADV
7 IPV6 * ICMP6 any Local any,any any,NDNBRSLCT
8 IPV6 * ICMP6 any Local any,any any,NDNBRADV
9 IPV6 * ICMP6 any Local any,any any,ECHOREQ
10 IPV6 default UDP any LU(30) any,161 any,any
11 IPV6 **nVSatellite UDP any LU(30) any,161 any,any
12 IPV6 default UDP any LU(30) any,162 any,any
13 IPV6 **nVSatellite UDP any LU(30) any,162 any,any
14 IPV6 default ICMP6 any LM[6] any,any any,MLDLQUERY
15 IPV6 default ICMP6 any LM[6] any,any any,LSTNRREPORT
16 IPV6 default ICMP6 any LM[6] any,any any,MLDLSTNRDN
17 IPV6 default ICMP6 any LM[6] any,any any,LSTNRREPORTv2
18 IPV6 * OSPF any LU(30) ff02::5,any any,any
19 IPV6 * OSPF any LU(30) ff02::6,any any,any
20 IPV6 * TCP any LU(30) any,any any,179
21 IPV6 * TCP any LU(30) any,179 any,any
22 IPV6 * ICMP6 any LU(30) any,any any,ECHOREPLY
23 IPV6 * ICMP6 any Local any,any any,UNREACH
24 IPV6 * ICMP6 any Local any,any any,PAK2BIG
25 IPV6 * ICMP6 any Local any,any any,TIMXCEED
26 IPV6 * ICMP6 any Local any,any any,HDRBAD
27 IPV6 * OSPF any LU(30) any,any any,any
28 IPV6 * TCP any LU(30) any,any any,any
29 IPV6 * UDP any LU(30) any,any any,any
30 IPV6 * any any LU(30) any,any any,any
The following is
another show command and its sample output:
RP/0/RSP1/CPU0:router# show lpts pifib hardware entry stat location 0/1/cpu0 | i IPV4 default | i TCP
14 IPV4 default TCP any LM[6] 6/0 any,65145 200.0.0.1,179 lpts_acl_1
15 IPV4 default TCP any LU(30) 0/0 any,179 200.0.0.1,any lpts_acl_1
16 IPV4 default TCP any LU(30) 0/0 any,23 any,any
NP Based
Policer
The following is a
sample NP based policer configuration:
RP/0/RSP0/CPU0:vkg1-lpts# lpts pifib hardware police location 0/1/CPU0
np np2 flow bgp known rate 50
np np3 flow ospf multicast known rate 100
!
lpts pifib hardware police
!
The following is a
show command and its sample output for the preceding policer configuration:
RP/0/RSP1/CPU0:router# show lpts pifib hardware entry np 3 statistics location 0/1/CPU0
Node: 0/1/CPU0:
----------------------------------------
L3 - L3 Protocol;L4 - Layer4 Protocol; Intf - Interface;
Dest - Destination Node;
LU - Local chassis fabric unicast;
LM - Local chassis fabric multicast;
RU - Multi chassis fabric unicast;
RM - Multi chassis fabric multicast;
na - Not Applicable or Not Available
Offset L3 VRD id L4 Intf Dest Pkts/Drops laddr,Port raddr,Port acl name
------ ---- ------------ ------ --------------- ----------- ---------------- --------------------- -----------------------------------
8 IPV4 * any any Local 0/0 any,any any,any
9 CLNS * - any LU(30) 0/0 - -
10 IPV4 * ICMP any Local 0/0 any,any any,ECHO
11 IPV4 * OSPF Optimized LU(30) 0/0 224.0.0.5,any any,any
12 IPV4 * OSPF Optimized LU(30) 0/0 224.0.0.6,any any,any
13 IPV4 * OSPF Optimized LU(30) 0/0 any,any any,any
14 IPV4 default TCP any LU(30) 0/0 any,23 any,any
15 IPV4 default L2TPV3 any LU(30) 0/0 any,any any,any
16 IPV4 * OSPF any LU(30) 0/0 224.0.0.5,any any,any
17 IPV4 * OSPF any LU(30) 0/0 224.0.0.6,any any,any
The following is
another show command and its sample output:
RP/0/RSP1/CPU0:router# show lpts pifib hardware police np np3 location 0/1/CPU0
Fri Mar 27 09:32:21.500 UTC
-------------------------------------------------------------
Node 0/1/CPU0:
-------------------------------------------------------------
Burst = 100ms for all flow types
-------------------------------------------------------------
FlowType Policer Type Cur. Rate Def. Rate Accepted Dropped TOS Value
---------------------- ------- ------- ---------- ---------- -------------------- -------------------- ----------
unconfigured-default 100 Static 2500 2500 0 0 01234567
L2TPv2-fragment 185 Static 10000 10000 0 0 01234567
Fragment 101 Static 2500 2500 0 0 01234567
OSPF-mc-known 102 np 100 2000 0 0 01234567
OSPF-mc-default 103 Static 1500 1500 0 0 01234567
OSPF-uc-known 104 Static 2000 2000 0 0 01234567
OSPF-uc-default 105 Static 1000 1000 0 0 01234567
ISIS-known 143 Static 2000 2000 0 0 01234567
ISIS-default 144 Static 1500 1500 0 0 01234567
BFD-known 150 Static 9600 9600 0 0 01234567
BFD-default 160 Static 45340 9600 0 0 01234567
BFD-MP-known 178 Static 11520 11520 0 0 01234567
BFD-MP-0 179 Static 128 128 0 0 01234567
BFD-BLB-known 183 Static 11520 11520 0 0 01234567
BFD-BLB-0 184 Static 128 128 0 0 01234567
BFD-SP-0 182 Static 512 512 0 0 01234567