[c-nsp] Rate limiting via radius

Oliver Boehmer (oboehmer) oboehmer at cisco.com
Thu May 4 13:04:54 EDT 2006


Paul Stewart <mailto:pstewart at nexicomgroup.net> wrote on Thursday, May
04, 2006 6:10 PM:

> Sorry to bump my own post...;)
> 
> I'm getting much "warmer" now...
> 
> acs1-con-mb#sh interfaces vi988 rate-limit
> Virtual-Access988
>   Input
>     matches: all traffic
>       params:  128000 bps, 7500 limit, 7500 extended limit
>       conformed 1402 packets, 123100 bytes; action: transmit
>       exceeded 11 packets, 16566 bytes; action: drop
>       last packet: 3560ms ago, current burst: 6988 bytes
>       last cleared 00:00:32 ago, conformed 30000 bps, exceeded 4000
>   bps Output
>     matches: all traffic
>       params:  3000000 bps, 7500 limit, 7500 extended limit
>       conformed 2353 packets, 3453865 bytes; action: transmit
>       exceeded 59 packets, 88845 bytes; action: drop
>       last packet: 3592ms ago, current burst: 0 bytes
>       last cleared 00:00:32 ago, conformed 862000 bps, exceeded 22000
> bps
> 
> This is working now with a test account... But we're not getting
> nearly the speeds we should... Above we should see "roughly" 128kb/s
connect
> speed and running a local speed test we're only seeing about 38kb/s  -
> same on output, it's roughly 2 meg

what does the CPU say? "show int vi988 stat" shows packets being
process-switched (because you're using TCP header-compression)?

	oli



More information about the cisco-nsp mailing list