Nortel Networks 5520, 5530 Configuration Example 3 Port Range Using ACL or Policy, TCP Port Range

Page 60

 

Filters and QoS Configuration for ERS 5500

 

 

 

 

 

 

Technical Configuration Guide

v2.0

 

NN48500-559

 

 

 

 

 

 

 

_____ ____________________________

________ ____ _________

________

 

 

1

one

Enabled

IP

1/3

NonVol

 

 

2

one

Enabled

IP

1/4

NonVol

 

 

3

one

Enabled

IP

1/5

NonVol

 

 

4

one

Enabled

IP

1/6

NonVol

 

 

5

two

Enabled

IP

1/8

NonVol

 

 

6

two

Enabled

IP

1/9

NonVol

 

 

7

two

Enabled

IP

1/10

NonVol

 

12.4Configuration Example 3: Port Range Using ACL or Policy

Assuming we wish to filter on the following port ranges and remark the traffic to CoS level shown below:

TCP dst-port 80-127 with CoS level of Gold

UDP dst-port 2000-2047 with CoS level of Silver

As mentioned in section 3.3, a port range must start with an even minimum number while the maximum number rightmost consecutive 0’s are replaced with 1’s. The table shown below displays the valid ranges that can be configured.

Table 9: Port Range

Protocol

Port or Port

Min/Max Range

Valid Ranges

 

Range

Binary Value

((Port Min + 2n) -1))

TCP Port Range: 80-127

 

 

TCP

80-95

Min = 1010000

Max Port Range: 80-95

 

 

Max = 1011111

Other valid ranges:

 

 

 

80 to 80

 

 

 

80 to 81

 

 

 

80 to 83

 

 

 

80 to 87

TCP

96-127

Min = 1100000

Max Port Range: 96-127

 

 

Max = 1111111

Other valid ranges:

 

 

 

96 to 96

 

 

 

96 to 97

 

 

 

96 to 99

 

 

 

96 to 103

 

 

 

96 to 111

UDP Port Range: 2000-2047

 

 

UDP

2000-2015

Min = 11111010000

Max Port Range: 2000-2015

 

 

Max = 11111011111

Other valid ranges:

 

 

 

000 to 2000

 

 

 

000 to 2001

 

 

 

000 to 2003

 

 

 

000 to 2007

UDP

2016-2047

Min = 11111100000

Max Port Range: 2016-2047

 

 

Max = 11111111111

Other valid ranges:

 

 

 

2016 to 2016

 

 

 

2016 to 2017

 

 

 

2016 to 2019

 

 

 

2016 to 2023

 

 

 

2016 to 2031

___________________________________________________________________________________________________________________________

Nortel Confidential Information Copyright © 2008 Nortel Networks. All Rights Reserved.

 

External Distribution

59

Image 60
Contents Ethernet Routing Switch NN48500-559 Abstract Table of Contents List of Figures List of TablesDocument Updates SymbolsConventions TextOverview Ethernet Routing Switch 5500 QoS and Filtering Classification Untrusted PortsUnrestricted Ports ƒ Layer 2 Classifier ElementsActions Supported StatisticsQoS Flow Chart Filter Functionality Overall Classification FunctionalityClassifier Block Functionality Port Range Functionality 7, 15, 31, 63 255, 511, 1025 4095, 8191 32762, or Min =Default Policy Drop Action PoliciesNN48500-559 5520-24T-PWRconfig#qos agent buffer large maximum regular 5520-24T-PWRconfig#default qos agent bufferQueue Sets Ethernet Routing Switch 5500 Egress CoS Queuing Egress CoS QueuingCoS 5520-24T-PWRconfig#show qos queue-set-assignment 5520-24T-PWRconfig#qos agent queue set5520-24T-PWRconfig#default qos agent queue-set 5520-24T-PWRconfig#qos agent reset-defaultEgress Queue Recommendations Traffic Meter and Shaping Bucket SizeActual Bucket Size Policing TrafficActual Bucket Size in Bytes Actual size in bytes Interface Parameter DescriptionExample Interface Shaper Meter Bucket Size and DurationBucket Size Max burst rate Committed rate Duration MSec 5530-24TFDconfig#show qos if-shaper port Default Nortel Class of Service Default Nortel CoS MarkingsBinary Hex DecimalQoS Access Lists ACL ACL ConfigurationIP-ACL Configuration Config#qos ip-acl name 1..16 character string ?2 L2-ACL Configuration ACL-Assign ConfigurationACL Configuration Example Config#qos l2-acl name 1..16 character string ?Verification 5530H-24TFD#show qos acl-assign5530H-24TFD#show qos ip-acl 5530H-24TFD#show qos policy 5500config#no qos acl-assign 5500config#no qos acl-assign 1 port 1/195500config#no qos ip-acl Changing ACLIP Security Features Dhcp Snooping ConfigurationDynamic ARP Inspection Configuration Dhcp SnoopingIP Source Guard Configuration IP Source GuardBpdu Filtering Configuration Bpdu FilteringQoS Applications Number of Classifiers Used Feature QoS Interface ApplicationsConfiguration Example ARP SpoofingDhcp Attacks Dhcp Snooping10.3 DoS Bpdu Blocking Configuration Steps Policy Configuration Role CombinationERS5500-48T#show qos if-assign ERS5500-48T#show qos if-groupERS5500-48Tconfig#qos ip-element 1-64000? ClassificationAdding IP and L2 Element IP ElementAdding a Classifier Adding a Classifier BlockMeters Parameters and variables DescriptionAdd a New Policy Configuration Examples Pre-defined ValuesQoS Action Configuration Example 1 Traffic Meter Using Policies 12.2.1 ERS5500 Configuration Using PoliciesConfigure the Interface Role Combination Configure the IP elementsConfigure Meters Configure the Classifier BlockERS5500 Create the classifier block Configure the Policy Verify OperationsERS5500 Create the policy Verify the Role CombinationVerify Classifier and Classifier Block Configuration Name m1ERS5500-24T#show qos classifier-block Verify Policy Configuration Verify that the QoS Policy 12.3.1 ERS5500 Configuration IP ACL, Dhcp Snooping, ARP Inspection, and Source GuardERS5500 Add IP address to Vlan 700 and enable Ospf ERS5500 Enable ARP-Inspection for VLAN’s 110 ERS5500 Assign the IP-ACL’s to ports Verify DHCP-SnoopingVerify ARP Inspection VIDVerify ACL Configuration Verify IP Source GuardNN48500-559 NN48500-559 ERS5500-24T#show qos acl-assign Configuration Example 3 Port Range Using ACL or Policy TCP Port RangeConfiguration Using Policies Configure the PoliciesERS5500 Create IP elements for UDP port range Configuration Using IP-ACL’s ERS5500 Remark all other traffic to Bronze12.5.1 ERS5500 Configuration Using Policies Create Policy12.5.2 ERS5500 Configuration Using IP-ACL’s ERS5500 Pass all other traffic with standard CoSERS5500 Assign the L2-ACL’s to ports Configuration Example 5 L2 and L3 Classification 12.6.1 ERS5500 Configuration Using PoliciesConfigure Classifier and Classifier Blocks ERS5500 Add L2 elements for Vlan 11012.7.1 ERS5500 Configuration Dscp Mapping via Un-restricted Port RoleACL Configuration Policy ConfigurationView the Queue Assignments ID IDConfiguration Example 7 Interface Shaping Enable Shaping on PortVerify Shape Rate Configuration Software Baseline Reference DocumentationContact us