Quick Reference Guide

430 PowerConnect B-Series TI24X Configuration Guide
53-1002269-02
ACL-based rate limiting using traffic policies
17
Support for fixed rate limiting and adaptive rate limiting
PowerConnect B-Series TI24X devices support the following types of ACL-based rate limiting:
Fixed rate limiting Enforces a strict bandwidth limit. The device forwards traffic that is within
the limit but either drops all traffic that exceeds the limit, or forwards all traffic that exceeds
the limit at the lowest priority level, according to the action specified in the traffic policy.
Adaptive rate limiting – Enforces a flexible bandwidth limit that allows for bursts above the
limit. You can configure Adaptive Rate Limiting to forward, modify the IP precedence of and
forward, or drop traffic based on whether the traffic is within the limit or exceeds the limit.
Configuring ACL-based fixed rate limiting
Use the procedures in this section to configure ACL-based fixed rate limiting. Before configuring
this feature, see what to consider in “Configuration notes and feature limitations” on page 427.
Fixed rate limiting enforces a strict bandwidth limit. The port forwards traffic that is within the limit.
If the port receives more than the specified number of fragments in a one-second interval, the
device either drops or forwards subsequent fragments in hardware, depending on the action you
specify.
To implement the ACL-based fixed rate limiting feature, first create a traffic policy, then reference
the policy in an extended ACL statement. Lastly, bind the ACL to an interface. Follow the steps
below.
1. Create a traffic policy. Enter a command such as the following.
PowerConnect(config)# traffic-policy TPD1 rate-limit fixed 100 exceed-action
drop
2. Create an extended ACL entry or modify an existing extended ACL entry that references the
traffic policy.
Example
PowerConnect(config)# access-list 101 permit ip host 210.10.12.2 any
traffic-policy TPD1
3. Bind the ACL to an interface.
PowerConnect(config)# int e 5
PowerConnect(config-if-e5)# ip access-group 101 in
PowerConnect(config-if-e5)# exit
The above commands configure a fixed rate limiting policy that allows port e5 to receive a
maximum traffic rate of 100 kbps. If the port receives additional bits during a given one-second
interval, the port drops the additional inbound packets that are received within that one-second
interval.
Syntax: [no] traffic-policy <TPD name> rate-limit fixed <cir value> exceed-action <action> [count]
Syntax: access-list <num> permit | deny.... traffic policy <TPD name>
Syntax: [no] ip access-group <num> in
NOTE
For brevity, some parameters were omitted from the above access-list syntax.