Cisco WAN :: Policing On 7613 SVI?

Aug 4, 2011

We have built some policers to apply to vlan SVIs on our 7613 so that we can rate limit input and output traffic.  We followed the Cisco formula and got this.
 
policy-map vlan-shape-3meg
  class class-default
   police cir 3000000 bc 562500 be 1125000    conform-action transmit     exceed-action drop     violate-action drop
  
There have been some complaints about this not actually meeting the limit.  When I do a show policy-map interface xxx I get this.  Based on that it looks like the Be value is being change to match the Bc value. 
 
On a separate note, I noticed that every policer we built with the cisco formula actually ends up with a Tc greater than the max Tc of .125 seconds. It seems odd that a recommended formula would end up creating values outside the maximum allowed limits by the software.
 
I'm not a QoS expert so if any of this seems like basic stuff it's just because I'm a little slow on QoS.   
 
Vlan2
   Service-policy input: temp-remove
   class-map: class-default (match-any)
Match: any
police :

[code]....
 
One other thing...in order to apply policers input and output on an SVI does mls qos vlan-based have to be configured on the trunks tagged with the corresponding Vlan?

View 1 Replies


ADVERTISEMENT

Cisco WAN :: 7613 - Way To Access NAM?

Feb 7, 2012

we have a Nam module on a 7613. I have access to the router. but how can i know the how to access the Nam?

View 1 Replies View Related

Cisco WAN :: 7613 Need To Connect To A Site

Feb 5, 2007

I have a cisco 7613 router and need to connect a site using Optical fibre (BSNL) on gigabit port,we will use convertor to convert optical signal to electrical .What configuration must be done on router to ensure this point to point fibre connectivity between my router and another router at differnt POp.

View 7 Replies View Related

Cisco :: 7613 Having Frequent High CPU Utilization?

Apr 25, 2012

I have Cisco 7613 on my edge(MPLS Backbone). CPU utilization is shooting to 100% at frequent intervals. When I tell vendors managing device they tell that it is happening due to one of my server(connected on Fast ethernet port of 100Mbps) generating heavy traffic. My questions are:

1. Can a router of 720Gbps capability be choked due to traffic generated by 100Mbps link?

2. Interrupt CPU process utilization is well below 10% at the said time. BGP router process consumes most of the CPU. Does this means that server in question is generating too many routing updates?

3. Is there any way that I can limit routing updates on a particular link?

4. how to check which link is causing more CPU utilization.

View 8 Replies View Related

Cisco WAN :: Output Drops On 7613 WS-X6748-GE-TX?

Jan 4, 2011

We have a 7613 w/ WS-SUP720-3BXL running 12.2(18)SXF11.  We have a 48 port WS-X6748-GE-TX that has one interface that keeps getting output drops for anything over 200Mb/sec.
 
See the attached file which has more details and show results. 

View 1 Replies View Related

Cisco WAN :: 7613 Can't Enter Port Adapter Module CPU

Feb 13, 2011

I have been using the Cisco7613 and FlexWAN with PA-8E1-IMA PortAdapter.It has been used for ITP (SIGTRAN) Today, I attemted to enter the Port Adapter 13 1 module with using command that "attach" command.But I couldn't that. and I could see the Error Message below." RTTYC_ ATTACH_ REQ Failed with return code 2 , aborting". This Module (13 1) is working normal. but why cannot enter to the PA ?

View 3 Replies View Related

Cisco WAN :: 7613 Serial Interface Showing Up But Can't Ping

Feb 24, 2013

What would cause an interface to show up/up (looped), but you still can't ping that loop?...It is on a Cisco 7613 with an Enhanced FlexWan (WS-X6582- 2PA), with a Mx Serial PA, 8 ports (73-1580-10) and running IOS ver 12.2(33)SRE2 [code]

View 5 Replies View Related

Cisco Infrastructure :: VLAN Are Not Available In Port Manager In 7613

Feb 25, 2005

I got a problem when I try to create a VLAN in a 7613 router.  The screen capature like the following:
 
router(conf)#vlan 1045
router(conf-vlan)#exit
VLAN(s) are not available in Port Manager
 
The VLAN is failed to create.  The VLAN range which is failed to create is from 1001 - 1060.

View 3 Replies View Related

Cisco WAN :: 7613 - Redundancy With WS-SUP720-3BXL Module

Mar 20, 2012

We have Router CISCO7613,SSO redundancy configured with two Sup 720-3BXL running 12.2(33)SRC1 image. Even thought I've configured SSO, my standby sup remains in COLD state with the following logs generated.
 
Mar 20 22:07:32.514 IST: %ISSU-SP-3-PEER_IMAGE_INCOMPATIBLE: Peer image (c7600s72033_sp-ADVENTERPRISEK9-M), version (12.2(33)SRC1) on peer uid (8) is incompatible
Mar 20 22:07:32.514 IST: %ISSU-SP-3-PEER_IMAGE_INCOMPATIBLE: Peer image (c7600s72033_sp-ADVENTERPRISEK9-M), version (12.2(33)SRC1) on peer uid (8) is incompatible
Mar 20 22:08:48.263 IST: %PFREDUN-SP-4-INCOMPATIBLE: Defaulting to RPR mode (Runtime incompatible)
[code]... 

These logs says that due to some reasons, the configuration is not being synchronized with active and standby sups and hence the redundancy mode remains in RPR mode and SSO not achieved, and hence COLD state. However, I couldn't find a reason why the configuration is not being synchronized, I've issued the command, redundancy config-sync ignore mismatched-commands, and everything worked fine, SSO achieved and standby sup came to HOT state.Now my query is, 

1. Why the configuration was not synchronized and standby SUP got in COLD state??
2. Since I issued the suggested command, at least, some of the mismatched lines in configuration will be ignored, Will that create a problem when my Active sup fails and standby become active?

View 4 Replies View Related

Cisco WAN :: 7613 - Traffic Move From Msfc To Fwsm?

Apr 4, 2013

I am planning to deploye the fwsm with all this complexity, will this type of senario work or not means traffic will move from msfc to the core.. Is this right to create another svi int2 on msfc to move traffic from msfc to core-switch.
 
G0/1(cisco7613) Vlan10----Vlan10(inside)FWSM-(outside)vlan20---Vlan20(inside)(svi-int1)MSFC(outside)(svi-int2)Vlan30---Vlan 30G0/2(Core-Switch)-----internet--->

View 5 Replies View Related

Cisco Firewall :: Moving IDSM-2 And FWSM From 7613 To 6513?

Feb 5, 2013

I need your opinion regarding moving of IDSM -2 and FWSM Module from 7613 to 6513 chassis.Currently these two modules are in 7613 and we are not using either of them now we have to configure them in 6513 chassis. As you can see from the figure that traffic of all 3 core router i.e 7613 go to 6513 - to proxy ISA 2004 - 6513 - to Internet.
 
There are also some network attached with 6513 and we want to move both of modules to 6513 so that NetworkA/B/C/D/E which are attached to 6513 can also be configured for FWSM and IDSM -2.
 
I have a query regarding this migration:Do we need license for these two modules again for 6513 chassis?

View 2 Replies View Related

Cisco WAN :: QoS Policing / Shaping For ASA 5510

May 28, 2013

We are looking to implement a bandwidth policy for our Internet link.  What i would like to know is if we use a policing policy, will the exceeded dropped packets be resubmitted from the source?  Will the dropped packets be resubmitted?  Are there any differences besides this when using either policing or shaping policies?  Is one better than the other?
 
CISCO ASA 5510 IOS 8.2

View 3 Replies View Related

Cisco WAN :: Configuring QoS Policing In 2911?

Sep 27, 2012

I configuring QoS policing in a Cisco 2911 in a 128K/256/512 link, but when I apply the configuration in interface I receive the error below:
 
Configured Percent results in out of range kbps.Allowed range is 8-2000000. The present CIR value is 6. 
 
Current configuration : 191 bytes
!
interface GigabitEthernet0/1
description ***V-SAT***
bandwidth 128

[Code].....

View 7 Replies View Related

Cisco WAN :: Create Two SVI Int On MSFC To Enable Routing In Between Two VLANs On 7613 Chassis

Mar 12, 2013

is there any specific way to create the SVI Interface on MSFC , actually I need to create the two SVI Int on MSFC to enable routing in between two VLANs on 7613 chassis.

View 2 Replies View Related

Cisco WAN :: 7613 How To Adjust Change Over Buffer Size At Link-set Sub-command

Apr 13, 2011

I was wondering about command of Linkset subcommand at ITP7613.I have been using the Cisco7613 chassis for the ITP(SIGTRAN) service.
 
However, i know that the "tx-queue-depth" command is used for sctp multihoming buffersize that between primary and secondary path at the Link sub-command mode. but i can't adjust the changeover buffersize(retrieval buffer) that between link and another link at the Linkset subcommand mode.
It's above my comprehension.
 
My guess is that related to "plan-capacity-rcvd" command. it's right?I want to know command that adjust the buffersize of Link changeover.

View 0 Replies View Related

Cisco :: Policing In Multiple Context Mode?

Jan 4, 2012

I know most QoS capabilities aren't available in multiple context mode, but I need to do some really simple policing on one of my contexts. I just want to apply a hard 20Mbps cap on an interface. I've seen a few places that suggest that basic policing is possible in multiple context mode, but apparently not by the normal commands.

View 5 Replies View Related

Cisco Firewall :: QoS Policing Configuration On An ASA 5505?

Jun 10, 2013

I'm working on QoS policing configuration on an ASA 5505.The ASA is situated behind a cable modem which provides an SLA of 3.2Mbps out.I've configured a QOS policy to place VoIP and other essential traffic (RDP/Citrix/PCoIP) into a priority queue, whilst policing default class to 3.2Mbps to police out to the cable modem.I can see on the outside interface graphs that this is rating the output traffic down to 3.2Mbps as expected, but noticing at certain points of high output traffic drops down to 1.6Mbps.  I can't see anything obvious in syslog or any other areas to look, so looking for any pointers as to why the speed is suddenly dropping down.  Likewise if I rate the output to 2Mbps, it will suddenly drop down to 1Mbps at high output rates.the ASA is running on 8.0(5) and I enclose a copy of the sample QoS config below and attached a sanitized run config, as well as screenshot taken of the outside interface Bit Rates plus service-policy.
 
access-list VoIP-Traffic-OUT extended permit tcp 172.16.6.0 255.255.255.0 host 68.98.217.252 eq h323
access-list VoIP-Traffic-OUT extended permit udp 172.16.6.0 255.255.255.0 host 68.98.217.252 object-group rtp
access-list VoIP-Traffic-OUT extended permit tcp 172.16.6.0 255.255.255.0 host 68.98.217.252 eq 2000  
access-list VMs-Traffic-Out extended permit tcp 172.16.6.0 255.255.255.0 192.168.168.0 255.255.255.0 eq 3389
access-list VMs-Traffic-Out extended permit tcp 172.16.6.0 255.255.255.0 192.168.168.0 255.255.255.0 eq citrix-ica
access-list VMs-Traffic-Out extended permit tcp 172.16.6.0 255.255.255.0 192.168.168.0 255.255.255.0 eq 4172

[code]....

View 6 Replies View Related

Cisco WAN :: ASR1001 / Traffic Policing And Shaping

Feb 25, 2012

I want to take 100Mb incoming from a service provider and police it off into several VRFs for customers.One of these VRFs will be 30M.I further need to traffic shape this (30Mb) out to 40 x 0.75Mbps (burstable to 30M) customers.
 
I am using an ASR1001.

View 2 Replies View Related

Cisco Firewall :: 5510 QoS Policing Giving More Bandwidth

May 5, 2011

I'm working in my lab trying to do proof of concept for traffic policing on the ASA 5510 running 8.0(4).  I have two laptops running Ubuntu one on the outside and one on the inside.  Both laptops have 100Mbps interfaces.  My tests consists of downloading a file from one laptop using HTTP.  Without any QoS I can see speeds close to 100Mbps which I would expect.  On a side note, try using XP and you won't come close to those speeds.  Anyhow,  I implement policing using the config below and expect to see the max rate on the laptops during the transfer max out close to the CIR.  However, I see speeds much higher on the laptops.
 
When I set the CIR to 10000 bps with bc at 1500 bytes I get speeds that range from 300Kbps to 700Kbps.  I would expect to see speeds max out at the CIR which would be 10Kbps.I'm having a hard time understanding why my numbers don't match.

View 6 Replies View Related

Cisco Switching/Routing :: Nexus 3048 QoS Policing

May 29, 2012

Any way of policing traffic on the Nexus 3k platform?  I can't find a reference to say policing/shaping is supported.

View 5 Replies View Related

Cisco Switching/Routing :: Policing Traffic On 4510?

Nov 21, 2012

I have two servers on one subnet that each need to replicate to a single server on another subnet. They also need to replicate to each other. This replication is unidirectional so I will refer to the 2 server subnet as the source subnet and the single server subnet as the destination subnet. In order to keep this replication running without killing the MPLS links on either end, we are trying to use a policy-map that limits bandwidth from the source subnet.The Problem:We have created a policy that polices traffic during specific times of day and limits the bandwidth as prescribed, however, bandwidth is also being limited between the 2 servers on the source subnet which is not needed or desired.Class 512K set dscp ef police 1024000 bps 1024000 byte conform-action transmit exceed-action dropClass Map match-any 512K (id 4) Match access-group name DAGExtended IP access list DAG 10 permit ip host 10.20.0.3 host 10.20.0.10 time-range DAG-REP (active) (22793 matches) 20 permit ip host 10.20.0.4 host 10.20.0.10 time-range DAG-REP (active) (14156 matches)The service policy is applied on the input side of the 2 interfaces on which our devices are connected.As you can see, the access list identifies the interesting traffic as traffic from two specific hosts to one specific host. The problem we are having is that bandwidth is also being throttled between the two source hosts even though it is not defined to do so.What can I do to limit traffic from the two source devices to the single destination device without limiting bandwidth between the two source devices?

View 1 Replies View Related

Cisco Switching/Routing :: C3750 - ACL Building For QOS Or Policing

Jun 6, 2012

I would like to apply policing on a C3750 interface, for all traffic matching 10.0.0.0 / 8, except for sub net 10.0.0.0 / 24. I plan to apply the following configuration, with an ACL that denies 10.0.0.0 / 24 then accept 10.0.0.0 / 8. I am quite sure of the answer but need a confirmation about the following configuration correct ? (10.0.0.0 / 24 will be not blocked, and no policing will be apply on it?)
 
ip access-list extended TEST
deny tcp 10.0.0.0 0.0.0.255 any eq 5000
permit tcp any 10.0.0.0 0.255.255.255 any eq 5000
[code]....

View 2 Replies View Related

Cisco Switching/Routing :: 3560 Egress Policing And Classification

Jan 17, 2012

I have a customer who requires to identify and police traffic on egress on a 3560 trunk link.  I cannot use ingress classifications because we do not know what route the traffic will take yet.  The egress interface connects to multipoint wireless equipment with 4 different bandwidth point to point links. So the ingress traffic may be routed via any one of 4 point to point wireless links connected to the single egress interface.  Am I correct in assuming we cannot mark on the egress direction then put the traffic in a SRR shaped egress queue based on the marking ? So we would only have the option to egress queue based on markings applied or trusted on the inbound direction ? I had thought of some kind of policy map/aggregate policer configuration based on the exit VLAN but it seems we can only apply this type of config inbound. From reading the 3560 configuration guides it seems the 3560 cannot deploy the kind of requirements this customer needs.  Perhaps they should have deployed some kind of Metro switch ?

View 1 Replies View Related

Cisco WAN :: Traffic Policing On 7609 With ES20 Line Card

May 5, 2013

I am trying to configure traffic policing on a 7609 with ES20 line card - however it doesn't appear to be working.  The customer is randomly getting DoS attacked, and the policy doesn't appear to be dropping any exceed/violate traffic.This is an egress policy on a sub-interface. 

View 5 Replies View Related

Cisco Switching/Routing :: 3750x Inbound Port Policing?

Dec 11, 2012

dont seem to be able to get policing working inbound on a port 3750X v 15.0(2)
 
Config is below:
 
ip access-list extended SMB
permit tcp host 192.168.1.14 host 172.16.1.30
permit tcp host 192.168.1.14 host 172.16.1.31

[Code]....

View 6 Replies View Related

Cisco Switching/Routing :: IPv6 Filtering / Policing On 2960 Switch?

Jan 3, 2012

Trying to control capacity utilization for guest users connecting to a 2960 switch. No problem for IPv4 users, but IPv6 is giving me fits. What I've found out by trial and error so far implies that there is just enough IPv6 smarts in a WS-C2960-24TT-L running c2960-lanbasek9-mz.150-1.SE to make it impossible to control IPv6 traffic. Blocking IPv6 would be sufficient short term, but MAC filtering on type 0x86DD does not appear to work either. Here are the results I've gotten so far:
 
What "works":

*  Protocol ipv6 or an IPv6 ACL in a class map.

* Using a class map referencing ipv6 protocol or an ipv6 ACL in a policy map.

* IPv4 inbound filters and policing.

* Blocking of IPv4 traffic by a MAC ACL blocking type 0x0800 (IPv4) - note that the docs explicitly state that MAC filters do NOT filter IP traffic, except for on this box on this release they do.
 
What does not work:
 
* Applying a policy map referencing a class map referencing protocol ipv6 or an IPv6 ACL to an interface. The service policy is accepted by the parser, but is not inserted into the running configuration.

* "class-default" in a policy map only matches IPv4 traffic, not all other traffic.

* Blocking of IPv6 traffic by a MAC ACL blocking type 0X86DD. No problem applying the access-group to the interface, it just doesn't do anything.
 
I am aware that this box is not supposed to support IPv6 other than for multicast, but as implemented, this is a hole an abuser could drive a MAC truck through.
 
My questions:
 
Is this situation unique to this particular 2960 switch or SW release (I also tried 12.2(58)SE2) or does it afflict all 2960's running LANbase?
 
Assuming the answers to the first two question are negative, what is the minimum requirement to get working IPv6 policing in an edge switch?

View 0 Replies View Related

Cisco WAN :: C7200-IK9SU2-M / QoS Traffic Shaping Not Working (but Policing Does Work)

Feb 8, 2011

I have lots of PPPoE users that get Virtual Access interfaces created upon login based on a virtual template. I need to traffic shape them. I know how to get it to work on an individual basis, because the policing within a service policy works fine. As soon as i change it to shaping it leaves things wide open.I really dont care how it gets done, I just need to be able to specify a speed to be traffic shaped and apply that to a virtual template. I need to limit speeds on the download and upload, i understand that the upload i will use the policing, but the download i need it to smooth out the flow and be traffic shaped, not policed.
 
Here is my Policies and classes:

***
policy-map CHILD class class-default  bandwidth 1650policy-map PARENT class class-default  shape average 1650000  service-policy CHILD****
Here is my Virtual Template:
****
interface Virtual-Template8 description pppoe-auth-FTTH ip unnumbered FastEthernet0/0 ip access-group subs-in-FTTH in ip mtu 1493 timeout absolute 6120 0 peer default ip address pool FTTH-POOL ppp authentication pap pppoe-auth ppp authorization pppoe-auth ppp timeout idle 84600 service-policy output PARENT

[code]....
 
The results i am getting is unrestrcited throughput, i am seeing about 40mb of throughput when the target is to limit to 1.65MB. As you can see from the output the PARENT class is seeing 279116 packets, but the shaper only saw 59. In all the examples i see on the internet these two numbers should be the same. Why is the shaper not acting on all the traffic crossing that class/policy?
 
Hardware/IOS:
Cisco IOS Software, 7200 Software (C7200-IK9SU2-M), Version 12.4(12), RELEASE SOFTWARE (fc1)

View 11 Replies View Related

Cisco Firewall :: 5505 - How To Apply Policing On ASAs With Leased Lines

Jul 2, 2012

I'm trying to configure policing and/or shaping on a setup of 2 x ASA 5505 Sec Plus. The units are placed in office A and office B and each have a ISP connection to the internet and a leased line with a capacity of 4/4 Mbit/s for interoffice communication.
 
On each ASA there's four subnets. VLAN 200 is used to connect the offices through the leased line.
 
Subnets:
Outside = 2
Data = 10
Voice = 100
Linknet = 200
 
I've read a lot of articles and posts about shaping and policing on the ASA but still can't get it to work like I wan't to. I'm trying to limit all traffic besides IP-telephony traffic to 3 Mbit/s and thus reserving 900 Kbit/s for voice traffic. I tried setting a service-policy on the linknet interface on each ASA and set Traffic match to Any traffic and QoS settings for both input and output.
 
I can see traffic passing the policy when I run the "show service-policy police" command but it never seems to be high enough to be policed which is strange since the ASDM monitoring shows that I'm pushing 3900 kbit/s. I file transfers verifies that policing does'nt work.

View 2 Replies View Related

Cisco Switching/Routing :: 3560 Rate-limit Vs Policing And Shaping

Nov 27, 2011

I am configuring a 3560 to provide internet access for our customers and I need to make sure they don't use more bandwidth than they have contracted for.I see that the 3560 supports the rate-limit command, but was told that I should use traffic shaping and policing along with access lists to manage the bandwidth.Is there a reason that I should avoid using the rate-limit command - it looks much simpler.

View 10 Replies View Related

Cisco Firewall :: ASA5550 - Implement Traffic Shaping / Policing Primarily For P2P Traffic?

Mar 10, 2011

We are looking to implement traffic shaping/policing primarily for P2P traffic. As natively the ASA5550 is only capable of p2p inspection if the traffic is tunneled via port 80 is the AIP-SSM the way forward? We have 2 5550s in active/active failover config. As a side note we are also looking to implement an IDS/IPS system so could this module cover all?Is this module going to provide the desired outcome or is there another module/device out there better suited for this? I would prefer to use the ASA5550s as opposed to implementing another product if only that we can make use of the investment we already made on these devices.

View 1 Replies View Related

Cisco :: Test Fast Roaming Using A Cisco 2100 Series Controller And 2 1140 APs?

Jul 20, 2011

I'm trying to test fast roaming using a Cisco 2100 Series controller and 2 1140 APs. The initial authentication succeeds fine and the wireless connection works ok using WPA2+CCKM and LEAP with a Cisco ACS radius server.The problem is that the client does not attempt to preauthenticate with the other AP because the RSN Capabilities IE in the AP beacons and probe responses do not set the RSN Preauthentication capable bit. I can't figure out what it takes to get the APs to indicate to clients that it can do preauthentication. I'm been crawling through all the documentation I can find, to no avail.

View 1 Replies View Related

Cisco WAN :: Does Cisco Catalyst 2960-8TC Support Bandwidth Limit Control

Aug 22, 2011

We are about to share a 10 MBit ISP connection with 2 others companies, and they are going to split the bill up into 3,3 and 4 Mbit, so we where thinking that we could setup a switch before their and ours router and provide them with a static IP from our ISP. But is it possible to set a bandwidth limit on the ports of a Cisco Catalyst 2960-8TC, so that we can set a limit of 3,3 and 4 on 3 ports.

View 1 Replies View Related

Cisco Wireless :: WLAN Cisco / AP 3502e - How To Get PAT (Product Acceptance Test)

Dec 3, 2011

I want to PAT my project of WLAN and i attached the document, how I create the Testing Criteria of the said scenarios, PAT document includes WCS 7.0, WLC 5508, MSE 3310, Cisco AP 3502e and ACS 4.2.

View 0 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved