Reference Guide

ip access-list extended AF1-FB1
seq 5 permit ip host 23.64.0.2 any
seq 10 deny ip any any
!
ip access-list extended AF1-FB2
seq 5 permit ip host 23.64.0.3 any
seq 10 deny ip any any
!
ip access-list extended AF2
seq 5 permit ip host 23.64.0.5 any
seq 10 deny ip any any
FTOS#show cam layer3-qos interface gigabitethernet 4/49
Cam Port Dscp Proto Tcp Src Dst SrcIp DstIp DSCP Queue
Index Flag Port Port Marking
-----------------------------------------------------------------------
20416 1 18 IP 0x0 0 0 23.64.0.5/32 0.0.0.0/0 20 2
20417 1 18 IP 0x0 0 0 0.0.0.0/0 0.0.0.0/0 - 0
20418 1 0 IP 0x0 0 0 23.64.0.2/32 0.0.0.0/0 10 1
20419 1 0 IP 0x0 0 0 0.0.0.0/0 0.0.0.0/0 - 0
20420 1 0 IP 0x0 0 0 23.64.0.3/32 0.0.0.0/0 12 1
20421 1 0 IP 0x0 0 0 0.0.0.0/0 0.0.0.0/0 - 0
20422 1 10 0 0x0 0 0 0.0.0.0/0 0.0.0.0/0 14 1
24511 1 0 0 0x0 0 0 0.0.0.0/0 0.0.0.0/0 - 0
In the previous example, the ClassAF1 does not classify traffic as intended. Traffic matching the first match criteria is
classified to Queue 1, but all other traffic is classified to Queue 0 as a result of CAM entry 20419.
When you remove the explicit “deny any” rule from all three ACLs, the CAM reflects exactly the desired classification.
Example of Desired Traffic Classifications
FTOS#show cam layer3-qos interface gigabitethernet 4/49
Cam Port Dscp Proto Tcp Src Dst SrcIp DstIp DSCP Queue
Index Flag Port Port Marking
-------------------------------------------------------------------------
20416 1 18 IP 0x0 0 0 23.64.0.5/32 0.0.0.0/0 20 2
20417 1 0 IP 0x0 0 0 23.64.0.2/32 0.0.0.0/0 10 1
20418 1 0 IP 0x0 0 0 23.64.0.3/32 0.0.0.0/0 12 1
20419 1 10 0 0x0 0 0 0.0.0.0/0 0.0.0.0/0 14 1
24511 1 0 0 0x0 0 0 0.0.0.0/0 0.0.0.0/0 - 0
Create a QoS Policy
There are two types of QoS policies — input and output.
Input QoS policies regulate Layer 3 and Layer 2 ingress traffic. The regulation mechanisms for input QoS policies are
rate policing and setting priority values. There are two types of input QoS policies: Layer 3 and Layer 2.
Layer 3 — QoS input policies allow you to rate police and set a DSCP or dot1p value.
Layer 2 — QoS input policies allow you to rate police and set a dot1p value.
Output QoS policies regulate Layer 3 egress traffic. The regulation mechanisms for output QoS policies are rate limiting,
rate shaping, and WRED.
NOTE: When changing a "service-queue" configuration in a QoS policy map, all QoS rules are deleted and re-added
automatically to ensure that the order of the rules is maintained. As a result, the Matched Packets value shown in
the show qos statistics command is reset.
NOTE: To avoid issues misconfiguration causes, Dell Networking recommends configuring either DCBX or Egress
QoS features, but not both simultaneously. If you enable both DCBX and Egress QoS at the same time, the DCBX
configuration is applied and unexpected behavior occurs on the Egress QoS.
648