222 CHAPTER 23: QOS/QOS PROFILE CONFIGURATION GUIDE
rule 1 permit TCP source 192.168.0.1 0 destination-port eq www time-range tr2
#
interface Ethernet1/0/1
traffic-redirect inbound ip-group 3000 rule 0 interface Ethernet1/0/2
traffic-statistic inbound ip-group 3000 rule 1
#
time-range tr2 00:00 to 08:30 working-day
time-range tr2 18:00 to 24:00 working-day
time-range tr2 00:00 to 24:00 off-day
time-range tr1 08:30 to 18:00 working-day
#
Precautions Note that:
The ACL rules configured for traffic classification must be permit statements.
When redirecting a packet, the switch processes the packet with the
forwarding mechanism instead of leaving it intact.
With traffic redirection configured, the switch does not forward the packets to
be redirected as usual.
The packets received on the destination port for redirection are tagged.
Configuring QoS Profile
Network Diagram Figure65 Network diagram for QoS profile configuration
Networking and
Configuration
Requirements
A company uses a switch (a Switch 5500 in this example) to interconnect all the
departments. The 802.1x protocol is used to authenticate the users and control
user access to the network resources. A user named someone in the test.net
domain is connected to Ethernet 1/0/1 of the switch. Its password is hello.
Configure a QoS profile to limit the outgoing IP traffic rate of the user someone
to 128 kbps after the user passes the 802.1x authentication, and drop the packets
exceeding the rate limit.
User
Switch
Network
AAA Server
Eth1/0/1