Overview
Copyright © 2016, Juniper Networks, Inc.
Single-rate two-color policing enforces a configured rate of traffic flow for a particular
service level by applying implicit or configured actions to traffic that does not conform
to the limits. When you apply a single-rate two-color policer to the input or output traffic
at an interface, the policer meters the traffic flow to the rate limit defined by the following
components:
Bandwidth limit—The average number of bits per second permitted for packets received
or transmitted at the interface. You can specify the bandwidth limit as an absolute
number of bits per second or as a percentage value from 1 through 100. If a percentage
value is specified, the effective bandwidth limit is calculated as a percentage of either
the physical interface media rate or the logical interface configured shaping rate.
Burst-size limit—The maximum size permitted for bursts of data. Burst sizes are
measured in bytes. We recommend two formulas for calculating burst size:
Burst size = bandwidth x allowable time for burst traffic / 8
Or
Burst size = interface mtu x 10
For information about configuring the burst size, see
for Traffic Policers" on page
NOTE:
There is a finite buffer space for an interface. In general, the
estimated total buffer depth for an interface is about 125 ms.
For a traffic flow that conforms to the configured limits (categorized as green traffic),
packets are implicitly marked with a packet loss priority (PLP) level of low and are allowed
to pass through the interface unrestricted.
For a traffic flow that exceeds the configured limits (categorized as red traffic), packets
are handled according to the traffic-policing actions configured for the policer. This
example discards packets that burst over the 15 KBps limit.
To rate-limit Layer 3 traffic, you can apply a two-color policer in the following ways:
Directly to a logical interface, at a specific protocol level.
As the action of a standard stateless firewall filter that is applied to a logical interface,
at a specific protocol level. This is the technique used in this example.
To rate-limit Layer 2 traffic, you can apply a two-color policer as a logical interface policer
only. You cannot apply a two-color policer to Layer 2 traffic through a firewall filter.
CAUTION:
You can choose either bandwidth-limit or bandwidth percent
within the policer, as they are mutually exclusive. You cannot configure a
Chapter 7: Basic Single-Rate Two-Color Policers
"Determining Proper Burst Size
30.
57
Need help?
Do you have a question about the EX9200 and is the answer not in the manual?