Configuring CAR

To apply a rate policy on an interface, you configure by using the rate-limit command in interface configuration mode. The following example limits all inbound FTP traffic on HssiO/ 0/0 to 240 kbps of bandwidth with 32 KB of burst. Inbound FTP traffic that exceeds the average rate (240 kbps) and the excess burst size (32 KB) is dropped.
interface Hssi0/0/0
rate-limit input access-group 101 240000 32O00 32000 conform-action transmit exceed-action drop
!
access-list 101 permit tcp any any eq ftp-data
access-list 101 permit tcp any eq ftp-data any
Notice these in the preceding example:
• The command rate-limit input access-group 101 240000 32000 32000 conforrn-action transmit excecd-action drop applies an input rate policy to the interface Hssi0/0/0. To configure a rate policy for outbound traffic, use the keyword output instead of input.
• The rate policy applies to packets received on the interface that match the criteria defined by access list 101 (FTP traffic to or from any source or destination). For more information on access lists, see Chapter 6, "Deploying Basic Security Services."
• Throughput is limited to 240 kbps of bandwidth and is allowed to burst above this average rate for 32 KB. Traffic that falls below 240 kbps is said to conform and is allowed through the interface (conform action transmit). Traffic that exceeds 240 kbps and bursts more than 32 KB is said lo exceed and is dropped (exceed-action drop).
Note Although the preceding example configures the exceed action as drop, a better drop policy is to use CAR to reclassify the non-conformant traffic to a lower precedence (exceed-action set-prec-transmit) and then use WRED to drop the lower precedence packets.
• The normal burst size and the excess burst size arc equal, meaning all traffic below 32 KB of burst is said to conform and all traffic above 32 KB of burst is said to exceed.
You can configure CAR on a VIP module (Cisco 7500 routers) and run it in distributed processing mode. Called distributed CAR (DCAR), this feature improves performance by moving CAR processing off of the router's main CPU and onto the VIP module. At the time of this writing, DCAR can scale to DS-3 (45 Mbps) and OC-3 (155 Mbps). depending on the VIP model. You must have DCEF enabled on the interface to enable DCAR (see "Configuring Cisco Express Forwarding," earlier in this chapter).
Defining Multiple Rate Policies
You can define more than one rate policy per interface. The following example sets rate policies for FTP traffic at 240 kbps. Web traffic at 600 kbps, and all other traffic at 160 kbps. Web traffic conforming to the rate policy is transmitted with precedence level 4, and Web traffic thai exceeds the rate policy is transmitted to precedence level zero (it is not dropped):
interface Hssi0/0/0
rate-limit input access group 101 240000 32000 32000 conform-action transmit exceed-action drop
rate limit input access-group 102 600000 24000 32000 conform-action set-prec-transmit
A exceed action set-prec- transmit 0 rate-limit input 160000 16000 24000 conform-action transmit exceed-action drop
I
access-list 101 perwit tcp any any eq ftp-data
access-list 102 permit tcp any any eq www
Notice these in the preceding example:
• The command rate-limit input access-group 101 240000 32000 32000 conform-action transmit exceed-action drop sets the same rate policy for FTP traffic as the previous example.
• The command rate-limit input access-group 102 600000 24000 32000 conform-action set-prec-transmit 4 exceed-action set-prec-transmit 0 sets an input rate policy for web traffic of 600 kbps with a normal burst size of 24 KB and an excess burst size of 32 KB. Web traffic conforming to this rate policy is transmitted with precedence level 4, and web traffic that exceeds this rate policy is transmitted with a precedence level zero. Here, instead of dropping the packets that exceed the policy, you are reclassifying them.
• The command rate-limit input 160000 16000 24000 conform-action transmit excced-action drop is a catchall for all other input traffic and sets the rate policy to 160 kbps with a normal burst size of 16 KB and an excess burst size of 24 KB. Traffic conforming to the policy is transmitted, and traffic that exceeds the policy is immediately dropped at the interface.
Using CAR Rate-Limit Access Lists
In addition to standard and extended access lists, you can match traffic by using two CAR-specific access lists called rate-limit access lists.
• IP precedence rate-limit access lists simply match packets that have a precedence value you define. The command is
access-list rate limit <l-99> <precedence value>
This access list, in conjunction with a rate policy, enables you to rate-limit traffic based on precedence values.
• MAC address rate-limit access lists match traffic that has a MAC address you define. The command for MAC address rate-limit access lists is
access-list rate-limit <100-199> <MAC addre$s>
• With MAC address rate-limit access lists, you can rate-limit traffic from a specific host or neighboring router. This can be useful when your router accepts traffic from a device outside of your control (at Internet exchange points, for example).
Using CAR to Classify Traffic
To classify packets (and not rate-limit them), configure both the conform action and the exceed action to set the precedence and transmit the packet. Here is an example:
interface Hssi0/0/0
rate-limit input access-group 101 240000 32000 32000 conform-action set prec-transmit 3 exceed-action set-prec transmit 3
!
access-list 101 permit tcp any any eq www
The command rate-limit input access-group 101 240000 32000 32000 conform-action set-prec-transmit 3 exceed-action set-prec-transmit 3 classifies all traffic matching access list 101 (all Web traffic) to precedence level 3, regardless of the traffic rate. Because the conform and exceed actions are the same, the bandwidth and burst numbers are unimportant.
Was this article helpful?
Readers' Questions
-
mark1 year ago
- Reply