Acl Metering-Blackdiamond 8800 Family And Summit X450 Only - Extreme Networks ExtremeWare XOS Guide Manual

Concepts guide
Hide thumbs Also See for ExtremeWare XOS Guide:
Table of Contents

Advertisement

Fragmented packet handling
Two keywords are used to support fragmentation in ACLs:
fragments—FO field > 0 (FO means the fragment offset field in the IP header.)—BlackDiamond 10K
only.
first-fragments—FO == 0.
Policy file syntax checker. The
syntax checker will reject such policy files.
Packet processing flow
The following rules are used to evaluate fragmented packets or rules that use the
keywords.
fragments
With no keyword specified, processing proceeds as follows:
An L3-only rule that does not contain either the
any IP packets.
An L4 rule that does not contain either the
fragmented or initial-fragment packets.
With the
keyword specified (BlackDiamond 10K only):
fragment
An L3-only rule with the
An L4 rule with the
fragments
With the
first-fragments
An L3-only rule with the
packets.
An L4 rule with the first-fragments keyword matches non-fragmented or initial fragment packets.
ACL Metering—BlackDiamond 8800 Family and Summit X450
Only
The BlackDiamond 8800 family and Summit X450 switches provide a metering capability which can be
used to associate an ACL rule to a specified bit-rate and out-of-profile action. The rate granularity is
64kbps (up to 1Gbps for GE ports and up to 10Gbps for 10G ports) and the out-of-profile actions are
drop, set the drop precedence, or mark the DSCP with a configured value. Additionally, each meter has
an associated out-of-profile byte counter which counts the number of packets that were above the
committed-rate (and subject to the out-of-profile-action).
To configure ACL metering, you will do the following steps:
1 Create the meter
2 Configure the meter
3 Associate the meter with an ACL rule entry
Creating the ACL Meter
To create the ACL meter, use the following command:
ExtremeWare XOS 11.3 Concepts Guide
keyword cannot be used in a rule with L4 information. The
fragments
fragments
fragments
keyword only matches fragmented packets.
fragments
keyword is not valid (see above).
keyword specified:
keyword matches non-fragmented or initial fragment
first-fragments
fragments
or
first-fragments
or
keyword matches non-
first-fragments
ACLs
or
first-
keyword matches
271

Advertisement

Table of Contents
loading

This manual is also suitable for:

Extremeware xos 11.3

Table of Contents