You're only matching the source host, which means that the OVERLIMIT class only matches inbound (to the router) traffic: > access-list 110 remark IPs to be rate limited > access-list 110 permit ip host 61.x.x.x any > access-list 110 permit ip any host 61.x.x.x