<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic QoS Policing on a LAC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541262#M1055238</link>
    <description>&lt;P&gt;Hi all, I've configured lac shaping for upload on my 2811 (ios xxx124-7.bin) as per:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/ps6350/products_configuration_guide_chapter09186a0080455ade.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/ps6350/products_configuration_guide_chapter09186a0080455ade.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However it's not working. I suspect IOS fault, just wanted to bounce it off someone else.... A "show policy-map session [uid]" gives me no output, eg:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;&lt;P&gt;rt2811_b101#show sss session&lt;/P&gt;&lt;P&gt;Current SSS Information: Total sessions 95&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Uniq ID Type       State         Service      Identifier           Last Chg&lt;/P&gt;&lt;P&gt;899     PPPoE/PPP  connected     Forwarded    x@x.x.x 11:53:01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rt2811_b101#&lt;/P&gt;&lt;P&gt;rt2811_b101#show policy-map session uid 899&lt;/P&gt;&lt;P&gt;rt2811_b101#&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Relevant components of the router configuration are: &lt;/P&gt;&lt;P&gt;==========================================&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;subscriber profile Profile1&lt;/P&gt;&lt;P&gt; service relay pppoe vpdn group group_1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn enable&lt;/P&gt;&lt;P&gt;vpdn source-ip x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn-group User2-vpdn-group-domain&lt;/P&gt;&lt;P&gt; request-dialin&lt;/P&gt;&lt;P&gt;  protocol l2tp&lt;/P&gt;&lt;P&gt;  domain y.y.y.y&lt;/P&gt;&lt;P&gt; initiate-to ip z.z.z.z&lt;/P&gt;&lt;P&gt; source-ip x.x.x.x&lt;/P&gt;&lt;P&gt; local name aName&lt;/P&gt;&lt;P&gt; ip tos max-reliability&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!arbitrary policing figure for testing purposes...&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map shape-128k&lt;/P&gt;&lt;P&gt;  description Throttle to 128K&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;  police cir 128000 bc 50000 be 100000&lt;/P&gt;&lt;P&gt;    conform-action transmit&lt;/P&gt;&lt;P&gt;    exceed-action drop&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bba-group pppoe global&lt;/P&gt;&lt;P&gt; ac name aName&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bba-group pppoe group_1&lt;/P&gt;&lt;P&gt; virtual-template 1&lt;/P&gt;&lt;P&gt; service profile Profile1&lt;/P&gt;&lt;P&gt; sessions per-mac limit 2&lt;/P&gt;&lt;P&gt; sessions per-vlan limit 250&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int fa0/0.x&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; pppoe enable group group_1&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Virtual-Template1&lt;/P&gt;&lt;P&gt; description PPPoE and L2TP&lt;/P&gt;&lt;P&gt; mtu 1492&lt;/P&gt;&lt;P&gt; ip unnumbered FastEthernet0/0.x&lt;/P&gt;&lt;P&gt; ppp authentication chap&lt;/P&gt;&lt;P&gt; ppp chap hostname aName&lt;/P&gt;&lt;P&gt; service-policy input shape-128k&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;==========================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, pppoe is WORKING, however upload policing isn't, which means I'm sending excess traffic across the WAN to be discarded at the LNS. Would be much nicer if it could be discarded at the LAC before uploading.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OH, and the Cisco feature navigator says LAC policing was implemented on IOS 12.3 for the Cisco 2811, so I don't think it's platform related....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated,&lt;/P&gt;&lt;P&gt;Cheers Muchly, Jerome&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:49:55 GMT</pubDate>
    <dc:creator>j.dolphin</dc:creator>
    <dc:date>2020-02-21T08:49:55Z</dc:date>
    <item>
      <title>QoS Policing on a LAC</title>
      <link>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541262#M1055238</link>
      <description>&lt;P&gt;Hi all, I've configured lac shaping for upload on my 2811 (ios xxx124-7.bin) as per:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/ps6350/products_configuration_guide_chapter09186a0080455ade.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/ps6350/products_configuration_guide_chapter09186a0080455ade.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However it's not working. I suspect IOS fault, just wanted to bounce it off someone else.... A "show policy-map session [uid]" gives me no output, eg:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;&lt;P&gt;rt2811_b101#show sss session&lt;/P&gt;&lt;P&gt;Current SSS Information: Total sessions 95&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Uniq ID Type       State         Service      Identifier           Last Chg&lt;/P&gt;&lt;P&gt;899     PPPoE/PPP  connected     Forwarded    x@x.x.x 11:53:01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rt2811_b101#&lt;/P&gt;&lt;P&gt;rt2811_b101#show policy-map session uid 899&lt;/P&gt;&lt;P&gt;rt2811_b101#&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Relevant components of the router configuration are: &lt;/P&gt;&lt;P&gt;==========================================&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;subscriber profile Profile1&lt;/P&gt;&lt;P&gt; service relay pppoe vpdn group group_1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn enable&lt;/P&gt;&lt;P&gt;vpdn source-ip x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn-group User2-vpdn-group-domain&lt;/P&gt;&lt;P&gt; request-dialin&lt;/P&gt;&lt;P&gt;  protocol l2tp&lt;/P&gt;&lt;P&gt;  domain y.y.y.y&lt;/P&gt;&lt;P&gt; initiate-to ip z.z.z.z&lt;/P&gt;&lt;P&gt; source-ip x.x.x.x&lt;/P&gt;&lt;P&gt; local name aName&lt;/P&gt;&lt;P&gt; ip tos max-reliability&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!arbitrary policing figure for testing purposes...&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map shape-128k&lt;/P&gt;&lt;P&gt;  description Throttle to 128K&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;  police cir 128000 bc 50000 be 100000&lt;/P&gt;&lt;P&gt;    conform-action transmit&lt;/P&gt;&lt;P&gt;    exceed-action drop&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bba-group pppoe global&lt;/P&gt;&lt;P&gt; ac name aName&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bba-group pppoe group_1&lt;/P&gt;&lt;P&gt; virtual-template 1&lt;/P&gt;&lt;P&gt; service profile Profile1&lt;/P&gt;&lt;P&gt; sessions per-mac limit 2&lt;/P&gt;&lt;P&gt; sessions per-vlan limit 250&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int fa0/0.x&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; pppoe enable group group_1&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Virtual-Template1&lt;/P&gt;&lt;P&gt; description PPPoE and L2TP&lt;/P&gt;&lt;P&gt; mtu 1492&lt;/P&gt;&lt;P&gt; ip unnumbered FastEthernet0/0.x&lt;/P&gt;&lt;P&gt; ppp authentication chap&lt;/P&gt;&lt;P&gt; ppp chap hostname aName&lt;/P&gt;&lt;P&gt; service-policy input shape-128k&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;==========================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, pppoe is WORKING, however upload policing isn't, which means I'm sending excess traffic across the WAN to be discarded at the LNS. Would be much nicer if it could be discarded at the LAC before uploading.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OH, and the Cisco feature navigator says LAC policing was implemented on IOS 12.3 for the Cisco 2811, so I don't think it's platform related....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated,&lt;/P&gt;&lt;P&gt;Cheers Muchly, Jerome&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541262#M1055238</guid>
      <dc:creator>j.dolphin</dc:creator>
      <dc:date>2020-02-21T08:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: QoS Policing on a LAC</title>
      <link>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541263#M1055241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Prerequisites for QoS: Classification, Policing, and Marking on LAC &lt;/P&gt;&lt;P&gt;Configure the Routers &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must configure the Client router, the LAC, and the LNS before applying the QoS policy map as described in the "Configuration Examples for QoS: Classification, Policing, and Marking on LAC" section. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify the State of the Subscriber Service Switch (SSS) Sessions &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must use the show sss session command to verify that the user sessions are enabled on the LAC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure the Interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must configure the virtual-template interface before applying the policy map to the session. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080455ade.html#wp1055864" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080455ade.html#wp1055864&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Apr 2006 16:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541263#M1055241</guid>
      <dc:creator>wong34539</dc:creator>
      <dc:date>2006-04-13T16:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: QoS Policing on a LAC</title>
      <link>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541264#M1055242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in addition to Phillip´s post, you might want to try and apply the service policy in the outbound direction as well.&lt;/P&gt;&lt;P&gt;Also, can you post the full configuration of your router ? Which feature set are you using (IP Base/Advanced etc.) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GNT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Apr 2006 20:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541264#M1055242</guid>
      <dc:creator>globalnettech</dc:creator>
      <dc:date>2006-04-13T20:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: QoS Policing on a LAC</title>
      <link>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541265#M1055243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Phillip, thanks for the reply. I've already tried what you've outlined. If you take a look at the information posted about you'll see the SSS sessions and the configured interface. Cheers, Jerome&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2006 00:06:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541265#M1055243</guid>
      <dc:creator>j.dolphin</dc:creator>
      <dc:date>2006-04-18T00:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: QoS Policing on a LAC</title>
      <link>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541266#M1055245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi GNT (no name on your profile)... Thanks for the response, appreciated..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running IOS "c2800nm-spservicesk9-mz.124-7.bin", Software Advisor says it supports LAC policing....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to the configuration originally posted I created the following....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;========================&lt;/P&gt;&lt;P&gt;policy-map shape-2048k&lt;/P&gt;&lt;P&gt;  description Throttle to 2048K&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;  police cir 2048000 bc 600000 be 1200000&lt;/P&gt;&lt;P&gt;    conform-action transmit&lt;/P&gt;&lt;P&gt;    exceed-action drop&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Virtual-Template1&lt;/P&gt;&lt;P&gt; description PPPoE and L2TP&lt;/P&gt;&lt;P&gt; mtu 1492&lt;/P&gt;&lt;P&gt; ip unnumbered FastEthernet0/0.30&lt;/P&gt;&lt;P&gt; ppp authentication chap&lt;/P&gt;&lt;P&gt; ppp chap hostname User2-lac-domain&lt;/P&gt;&lt;P&gt; service-policy input shape-128k&lt;/P&gt;&lt;P&gt; service-policy output shape-2048k&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;========================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That config change unfortunately hasn't made a difference, the "show policy map session uid [uid]" is still not giving me any output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a little reluctant to post the full configuration, what I put in the original post was all the LAC related stuff. Is there anything in particular you're looking for? I'll post it if you think it's really neccessary....?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers, Jerome&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2006 00:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-policing-on-a-lac/m-p/541266#M1055245</guid>
      <dc:creator>j.dolphin</dc:creator>
      <dc:date>2006-04-18T00:23:03Z</dc:date>
    </item>
  </channel>
</rss>

