Re: 3550 policing

From: James MacDonald (j4m3sm63@yahoo.ca)
Date: Wed Jul 11 2007 - 17:36:03 ART


Can you post your configuration? I've found in the past in 12.1(19)EA1 code on 3550-12T's you seem to need to match the vlan first then the IP in a separate class-map ... have no clue why. Subsequent testing seems to indicate you can do it with a single class-map match just the ip access-list ... you could simply be running into a bug.
 
------------------------------
Jim MacDonald
j4m3sm63@yahoo.ca
------------------------------

----- Original Message ----
From: Carlos G Mendioroz <tron@huapi.ba.ar>
To: ccielab@groupstudy.com
Sent: Wednesday, July 11, 2007 3:33:31 PM
Subject: 3550 policing

I'm trying to apply some rate limits to some traffic that
goes across a 3550.

Reading 3550 features, it's kind of clear that you should be able
to do that using MQC, using classes with only one match.
There are some restrictions, but it seems that 1 access group
based class (ip access list) with a police statement, applied
to an port in the ingress direction.

But it's not working. mls qos enabled, the policy is accepted, but
no traffic gets dropped. Actually, a show policy interface shows 0
packets conforming to the class, but I know that is not the case.
It seems I'm missing something...

Any ideas ?

-- 
Carlos G Mendioroz  <tron@huapi.ba.ar>  LW7 EQI  Argentina


This archive was generated by hypermail 2.1.4 : Sat Aug 18 2007 - 08:17:40 ART