We have applied Policy-map for limiting the BW of our Proxy server up to 20 Mbps.
Internet Link BW = 80 Mbps.
Internet Cloud ------ Internet CE router --------- Firewall -------- LAN ------- Proxy Server
We have applied following configuration on WAN interface of Internet CE router :
class-map match-any CM-XYZ-PROXY
match access-group name XYZ-PROXY
police 20000000 3750000 7500000 conform-action transmit exceed-action drop violate-action drop
description ***Tata Internet Link - WAN Interface - Outside ***
ip address 22.214.171.124 255.255.255.252
service-policy input PM-PROXY-LIMIT
ip access-list extended XYZ-PROXY
permit ip any host 126.96.36.199 time-range BUSSINESS
periodic daily 8:00 to 18:00
But than also in BW utilization graph and Netflow report we can see that the BW for the said Proxy server is going beyong 20 Mbps.
Is there any error in configuration?
Looks to me like the BW report is overall. Your configuration looks ok. Being that your policing is class based, the ACL statement permits any traffic to that specified destination, but looks like the report is overall. There could be other traffic on that interface going without being policed.
Could you please issue show policy-map interface Gi 0/1 to see the conformed/exceed packets?
Are you filtering based on the source IP address while pulling the reports for that WAN facing interface? Also that source ip address is of Proxy server? Anyways
Try changing this to simply
police 20000000 conform-action transmit exceed-action drop