02-29-2016 12:56 PM - edited 03-05-2019 03:27 AM
Hi
i have cisco 7600 rourer and im trying to do policy on the ether channel
the problem is i had done police , but there is no drop on interface and no drop rate on the policy map.
im wondering .... the router accepted the command .
but seems like no effect !!
------------
here is verification :
Gateway7600#sh int port-channel 30
Port-channel30 is up, line protocol is up (connected)
Hardware is EtherChannel, address is 503d.e5af.9c40 (bia 503d.e5af.9c40)
Internet address is 10.30.30.2/24
MTU 1500 bytes, BW 3000000 Kbit/sec, DLY 10 usec,
reliability 255/255, txload 176/255, rxload 13/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 1000Mb/s
input flow-control is off, output flow-control is off
Members in this channel: Gi1/5 Gi1/6 Gi1/8
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/3/3 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 154633000 bits/sec, 145079 packets/sec
5 minute output rate 2074069000 bits/sec, 213953 packets/sec
L2 Switched: ucast: 87979 pkt, 5750379 bytes - mcast: 81689 pkt, 13984306 bytes
L3 in Switched: ucast: 6453586221 pkt, 876697019075 bytes - mcast: 0 pkt, 0 bytes mcast
L3 out Switched: ucast: 9574779884 pkt, 11759331116192 bytes mcast: 0 pkt, 0 bytes
7000062608 packets input, 950857379119 bytes, 0 no buffer
Received 94375 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 0 multicast, 0 pause input
0 input packets with dribble condition detected
10440365833 packets output, 12822707781435 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 pause output
0 output buffer failures, 0 output buffers swapped out
Gateway7600#
Gateway7600#sh pol
Gateway7600#sh policy-map
Gateway7600#sh policy-map virus
Policy Map virus
Class class-default
police cir 1500000000 bc 46875000
conform-action transmit
exceed-action drop
Gateway7600#sh run int port-
Gateway7600#sh run int port-channel 30
Building configuration...
Current configuration : 98 bytes
!
interface Port-channel30
ip address 10.30.30.2 255.255.255.0
service-policy output virus
end
Gateway7600#
Gateway7600#sh pol
Gateway7600#sh policy-maqp
Gateway7600#sh policy-map
Gateway7600#sh policy-map int port-
Gateway7600#sh policy-map int port-channel 30
Port-channel30
Service-policy output: virus
class-map: class-default (match-any)
Match: any
police :
1500000000 bps 46875000 limit 46875000 extended limit
Earl in slot 1 :
3097996093069 bytes
5 minute offered rate 2058707184 bps
aggregate-forwarded 3097996093069 bytes action: transmit
exceeded 0 bytes action: drop
aggregate-forward 2034043424 bps exceed 0 bps
Gateway7600#
as u see , i limited to 1.5 G , but seems traffic already hit 2 G
any help ??
03-01-2016 10:57 PM
I don't know the answer. I wonder if this is being applied to the individual members rather than the channel itself.
Tried dividing the 1.5GB by the number of members in the channel and see if that makes any difference.
03-01-2016 11:51 PM
hi ,
sorry didnt understand you ,
the police is being applied on the port-channel now .
it has 3 members .
do you want me to apply the limitation under the members ?
or under both ?
cheers
03-02-2016 11:47 AM
I would try it on the port channel, but yes, divide it by 3.
I think what you have should already work ...
What supervisor have you got, and what version software are you running on it?
03-03-2016 02:17 AM
do you think its bug ?
or limitation ?
i dont want it on the individual , but i want it on the total interface of them which is portchannel ,
i have 3 links , the banlce on them not equal 100 %
========
here is what u asked me :
Gateway7600#sh module
Mod Ports Card Type Model Serial No.
--- ----- -------------------------------------- ------------------ -----------
1 9 Supervisor Engine 32 8GE (Active) WS-SUP32-GE-3B SAD104204GX
Mod MAC addresses Hw Fw Sw Status
--- ---------------------------------- ----- ------------- ------------ -------
1 0018.bad2.2324 to 0018.bad2.232f 4.4 12.2(18r)SX 15.2(4) Ok
Mod Sub-Module Model Serial Hw Status
---- --------------------------- ------------------ ----------- ------- -------
1 Policy Feature Card 3 WS-F6K-PFC3B SAD104201HK 2.3 Ok
1 Cat6k MSFC 2A daughterboard WS-F6K-MSFC2A SAD104004UC 3.1 Ok
Mod Online Diag Status
---- -------------------
1 Pass
Gateway7600#sh ve
Gateway7600#sh version
Cisco IOS Software, c7600s3223_rp Software (c7600s3223_rp-ADVENTERPRISEK9-M), Version 15.2(4)S, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2012 by Cisco Systems, Inc.
Compiled Fri 20-Jul-12 18:18 by prod_rel_team
ROM: System Bootstrap, Version 12.2(17r)SX3, RELEASE SOFTWARE (fc1)
BOOTLDR: Cisco IOS Software, c7600s3223_rp Software (c7600s3223_rp-ADVENTERPRISEK9-M), Version 15.2(4)S, RELEASE SOFTWARE (fc1)
Gateway7600 uptime is 3 days, 6 hours, 27 minutes
Uptime for this control processor is 3 days, 6 hours, 26 minutes
System returned to ROM by power-on (SP by error - a Software forced crash, PC 0x405ECBD4)
System image file is "sup-bootdisk:c7600s3223-adventerprisek9-mz.152-4.S.bin"
Last reload type: Normal Reload
Last reload reason: power-on
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
export@cisco.com.
cisco CISCO7604 (R7000) processor (revision 2.0) with 458752K/65536K bytes of memory.
Processor board ID FOX1509G2DK
R7000 CPU at 300MHz, Implementation 39, Rev 3.3, 256KB L2, 1024KB L3 Cache
Last reset from power-on
1 Virtual Ethernet interface
9 Gigabit Ethernet interfaces
1915K bytes of non-volatile configuration memory.
65536K bytes of Flash internal SIMM (Sector size 512K).
Configuration register is 0x2102
Gateway7600#
cheers
03-03-2016 10:04 AM
Are you able to upgrade the Sup32 to 12.2(33)SXH5?
I think it should work.
03-03-2016 12:00 PM
i will try
but will it support "shaping" on the out direction of portchannel ?
do you think so ?
03-03-2016 12:10 PM
It should support both shaping and policing on a port channel.
03-03-2016 10:10 PM
which one should i choose ?
https://software.cisco.com/download/release.html?mdfid=282201760&catid=268437717&release=12.2(33)SXH5&softwareid=280805692&sortparam=2
regards
03-03-2016 11:12 PM
Got my self confused there as well. Go to:
I would grab a gold star release, such as 12.2.33-SRE12 or 15.3.3S6.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide