04-04-2013 09:14 AM - edited 03-04-2019 07:29 PM
I've been having people downloading mail ost and hogging the bandwidth I setup shaping but doesn't seem to be working, i looked up different posts here and tried both policing and shaping but doesn't seem to be working.
This is over an MPLS network, and it happens acorss the board at different remote locations below is how I set it up but it doesn't seem to be helping, any advise/help is appreciated.
class-map match-any Shaped
description Exchange Server
match access-group 105
policy-map bandwidth-control
class Shaped
shape average 600000
!
!
!
!
!
interface FastEthernet0/0
no ip address
ip helper-address 192.168.0.26
duplex auto
speed auto
!
interface FastEthernet0/0.10
description Data VLAN 10
encapsulation dot1Q 10
ip address xxx.xx.x.1 255.255.255.0
ip directed-broadcast
service-policy output bandwidth-control
!
!
interface Serial0/0/0
ip address
ip flow ingress
encapsulation ppp
service-policy output llq
!
router bgp 65001
no synchronization
bgp log-neighbor-changes
redistribute connected
neighbor
no auto-summary
!
no ip forward-protocol nd
no ip http server
no ip http secure-server
access-list 105 permit ip any host 192.168.0.38
Thanks,
Solved! Go to Solution.
04-05-2013 09:26 AM
Hello
Clase based:
ip access-list extended server
permit ip any host 192.168.0.38
class-map match-all server_cm
match access-group name server
policy-map server_pm
class server_pm
police 6144000 192000 conform-action transmit exceed-action drop
int (lan facing)
service-policy input server_pm
CAR
access-list 100 permit ip any host 192.168.0.38
interface (wan)
rate-limit output access-group 100 6144000 115200 2304000 conform-action transmit exceed-action drop
res
Paul
Please don't forget to rate any posts that have been helpful.
Thanks.
04-04-2013 09:15 AM
By the way I set this configuration on the router at the location which is being affected with the bandwidth issue.
04-04-2013 10:35 AM
Hello,
Can you see that your ACL 105 is matched?
#show ip access 105
Can you provide detailed configuration, also with IP addresses (if some of them are public, show us at least first two octets)
Best Regards
Please rate all helpful posts and close solved questions
04-04-2013 12:37 PM
#sh ip access 105
Extended IP access list 105
10 permit ip any host 192.168.0.38
that's the IP of the exchange server.
04-04-2013 03:28 PM
Can you please post output of #sh ip cef 192.168.0.38 to verify my theory, if I will be right I will tell you what is it .
Best Regards
Please rate all helpful posts and close solved questions
04-04-2013 04:25 PM
sh ip cef 192.168.0.38
192.168.0.0/24
nexthop x.x.x.x Serial0/0/0
that's the public IP at nexthop.
What is your theory ?
the serial has the service-policy llq applied. does it need to be replaced with the bandwidth-control policy?
04-04-2013 11:53 PM
You applied service policy bandwidth-control on outband direction on Fa0/0.10 where packet with destination IP address of 192.168.0.38 should be matched by ACL 105. But this will never happen because packets destinated to 192.168.0.38 are routed out of Se0/0/0 interface.
You need to applied shaping policy on Se0/0/0 interface in outband direction or you need to apply policing on inbound direction of interface [shaping can not be applied in inbound direction] where are located users which will be shaped. If these users are located on multiple interfaces, only option is to apply shaping on Se0/0/0.
Best Regards
Please rate all helpful posts and close solved questions
04-05-2013 06:22 AM
Thanks I'll try that out when I get a chance and let you know how it went.
Thanks again!
04-05-2013 09:26 AM
Hello
Clase based:
ip access-list extended server
permit ip any host 192.168.0.38
class-map match-all server_cm
match access-group name server
policy-map server_pm
class server_pm
police 6144000 192000 conform-action transmit exceed-action drop
int (lan facing)
service-policy input server_pm
CAR
access-list 100 permit ip any host 192.168.0.38
interface (wan)
rate-limit output access-group 100 6144000 115200 2304000 conform-action transmit exceed-action drop
res
Paul
Please don't forget to rate any posts that have been helpful.
Thanks.
04-12-2013 01:03 PM
I tried the class based policing, today some users kept connecting/disconnecting from outlook. Is this common?
04-12-2013 05:36 PM
Hello
at the end of your policy map apply a
class class-default
and try an acl that permits all
res
paul
Sent from Cisco Technical Support Android App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide