Nortel Networks 5510, 5520, 5530 manual Configuration Example 5 L2 and L3 Classification

Page 65

Filters and QoS Configuration for ERS 5500

 

 

Technical Configuration Guide

v2.0

NN48500-559

12.6 Configuration Example 5 – L2 and L3 Classification

In this configuration example, the Ethernet Routing Switch is used as L2 switch with two VLANs providing L2 private VLAN services. Both VLAN’s have the same over-lapping IP addresses where workstation 1 and 2 are used to provide high-touch services. Overall, we wish to accomplish the following tasks:

Setup a policy to provide Gold service for host 1 and Silver service for host 2

For all other non-match traffic, set the default service class to Bronze service.

Figure 8: L2 and L3 Classification Example

The best way to accomplish these tasks is to:

Create a Role Combination for port 1/3

Create the first classifiers element with host 1’s IP address and VLAN 110 and add to Classifier Block 1 with an in-profile action of Gold Service

Create a second classifier element with host 2’s IP address and VLAN 120 and add to Classifier Block 1 with an in-profile action of Silver Service

Create a Policy with Classifier block 1 and the Role Combination for port 1/3 with a non- match action of Bronze Service

At this time, it is only possible to combine L2 and L3 filters using policies. It is not possible to combine IP-ACL’s with L2-ACL’s.

12.6.1 ERS5500 Configuration – Using Policies

12.6.1.1 Create a Separate Role Combination for Port 1/3

ERS5500 Step 1 – Add new role combination for port 1/3 configured as untrusted and add port member 1/3

ERS5500-24T(config)#qos if-group name Int_group_2 class untrustted

ERS5500-24T(config)#qos if-assign port 1/3 name Int_group_2

12.6.1.2 Add IP and L2 Classifiers Elements

ERS5500: Step 1 – Add IP elements with source address of 192.1.1.10

5500(config)#qos ip-element 1 src-ip 192.1.1.10/32

___________________________________________________________________________________________________________________________

Nortel Confidential Information Copyright © 2008 Nortel Networks. All Rights Reserved.

 

External Distribution

64

Image 65
Contents Ethernet Routing Switch NN48500-559 Abstract Table of Contents List of Tables List of FiguresSymbols Document UpdatesConventions TextOverview Ethernet Routing Switch 5500 QoS and Filtering Untrusted Ports ClassificationUnrestricted Ports ƒ Layer 2 Classifier ElementsStatistics Actions SupportedQoS Flow Chart Classifier Block Functionality Filter FunctionalityOverall Classification Functionality 7, 15, 31, 63 255, 511, 1025 4095, 8191 32762, or Min = Port Range FunctionalityPolicies Default Policy Drop ActionNN48500-559 Queue Sets 5520-24T-PWRconfig#qos agent buffer large maximum regular5520-24T-PWRconfig#default qos agent buffer Egress CoS Queuing Ethernet Routing Switch 5500 Egress CoS QueuingCoS 5520-24T-PWRconfig#qos agent queue set 5520-24T-PWRconfig#show qos queue-set-assignmentEgress Queue Recommendations 5520-24T-PWRconfig#default qos agent queue-set5520-24T-PWRconfig#qos agent reset-default Bucket Size Traffic Meter and ShapingPolicing Traffic Actual Bucket SizeActual Bucket Size in Bytes Actual size in bytes Interface Parameter DescriptionExample Bucket Size Max burst rate Committed rate Duration MSec Interface ShaperMeter Bucket Size and Duration 5530-24TFDconfig#show qos if-shaper port Default Nortel CoS Markings Default Nortel Class of ServiceBinary Hex DecimalACL Configuration QoS Access Lists ACLIP-ACL Configuration Config#qos ip-acl name 1..16 character string ?ACL-Assign Configuration 2 L2-ACL ConfigurationACL Configuration Example Config#qos l2-acl name 1..16 character string ?5530H-24TFD#show qos ip-acl Verification5530H-24TFD#show qos acl-assign 5530H-24TFD#show qos policy 5500config#no qos acl-assign 1 port 1/19 5500config#no qos acl-assign5500config#no qos ip-acl Changing ACLDhcp Snooping Configuration IP Security FeaturesDynamic ARP Inspection Configuration Dhcp SnoopingIP Source Guard IP Source Guard ConfigurationBpdu Filtering Bpdu Filtering ConfigurationQoS Interface Applications QoS Applications Number of Classifiers Used FeatureARP Spoofing Configuration ExampleDhcp Snooping Dhcp Attacks10.3 DoS Bpdu Blocking Role Combination Configuration Steps Policy ConfigurationERS5500-48T#show qos if-assign ERS5500-48T#show qos if-groupClassification ERS5500-48Tconfig#qos ip-element 1-64000?Adding IP and L2 Element IP ElementAdding a Classifier Block Adding a ClassifierParameters and variables Description MetersAdd a New Policy QoS Action Configuration ExamplesPre-defined Values 12.2.1 ERS5500 Configuration Using Policies Configuration Example 1 Traffic Meter Using PoliciesConfigure the Interface Role Combination Configure the IP elementsERS5500 Create the classifier block Configure MetersConfigure the Classifier Block Verify Operations Configure the PolicyERS5500 Create the policy Verify the Role CombinationName m1 Verify Classifier and Classifier Block ConfigurationERS5500-24T#show qos classifier-block Verify Policy Configuration Verify that the QoS Policy IP ACL, Dhcp Snooping, ARP Inspection, and Source Guard 12.3.1 ERS5500 ConfigurationERS5500 Add IP address to Vlan 700 and enable Ospf ERS5500 Enable ARP-Inspection for VLAN’s 110 Verify DHCP-Snooping ERS5500 Assign the IP-ACL’s to portsVID Verify ARP InspectionVerify IP Source Guard Verify ACL ConfigurationNN48500-559 NN48500-559 ERS5500-24T#show qos acl-assign TCP Port Range Configuration Example 3 Port Range Using ACL or PolicyERS5500 Create IP elements for UDP port range Configuration Using PoliciesConfigure the Policies ERS5500 Remark all other traffic to Bronze Configuration Using IP-ACL’sCreate Policy 12.5.1 ERS5500 Configuration Using PoliciesERS5500 Assign the L2-ACL’s to ports 12.5.2 ERS5500 Configuration Using IP-ACL’sERS5500 Pass all other traffic with standard CoS 12.6.1 ERS5500 Configuration Using Policies Configuration Example 5 L2 and L3 ClassificationERS5500 Add L2 elements for Vlan 110 Configure Classifier and Classifier BlocksDscp Mapping via Un-restricted Port Role 12.7.1 ERS5500 ConfigurationPolicy Configuration ACL ConfigurationID ID View the Queue AssignmentsVerify Shape Rate Configuration Configuration Example 7 Interface ShapingEnable Shaping on Port Reference Documentation Software BaselineContact us