[c-nsp] 7600 SVI (vlan interface) Policing

ar ar_djp at yahoo.com
Sat Dec 3 01:52:10 EST 2011


Based on this article: http://www.scribd.com/doc/36278538/Cisco-QoS-6500-7600-Indepth-Design (see notes below),

ingress policing can be applied on vlan interfaces and L2 switch ports, routed ports.

But based on my testing, it seems only egress policing is working on vlan interfaces. It's not policing the ingress traffic.

Anyone has experience on this?

>From the article:

"While Ingress Policing can be applied to a physical Layer 2 or Layer switch-port, a Routed port
or a Switched Virtual Interface (i.e. VLAN interface), Egress policing can apply a policy to all of these
interfaces except a physical Layer 2 switch-port. An Egress Policer cannot be applied to a Layer 2 switch-
port as it can with Ingress
 Policing. When the Policy Feature Card performs both Ingress and Egress
policing, it will process ingress policer before egress policer. It is also worth noting that an Ingress and
Egress policer can exist on a physical interface (or VLAN interface) at the same time."

More information about the cisco-nsp mailing list