23-17
Cisco Systems IntelligentGigabit Ethernet Switch Modules for the IBM BladeCenter, Software Configuration Guide
24R9746
Chapter23 Configuring QoS
Configuring Standard QoS
All ingress QoS processing actions apply to control traffic (such as spanning-tree bridge protocol
data units [BPDUs] and routing update packets) that the switch receives.
Only an ACL that is created for physical interfaces can be attached to a class map.
Only one ACL per class map and only one match command per class map are supported. The ACL
can have multiple access control entries, which are commands th at match fields against the contents
of the packet.
Policy maps with ACL classification in the egress direction are not supported and cannot be attached
to an interface by using the service-policy input policy-map-name interface configuration
command.
In a policy map, the class named class-default is not supported. The switch does not filter traffic
based on the policy map defined by the class class-default policy-map configuration command.
For more information about guidelines for configuring ACLs, see the “Classification Based on QoS
ACLs” section on page23-5.
For information about applying ACLs to physical interfaces, see the “Guidelines for Applying ACLs
to Physical Interfaces” section on page 22-5.
If a policy map with a system-defined mask and a security ACL with a user-defined mask are
configured on an interface, the switch might ignore the acti ons specified by the policy map and
perform only the actions specified by the ACL. For information about masks, se e the
“Understanding Access Control Parameters” section on page 22-4 .
If a policy map with a user-defined mask and a security ACL with a user-defined mask are
configured on an interface, the switch takes one of the actions a s described in Tabl e 23-5 . For
information about masks, see the “Understanding Access Control Parameters” section on page 22-4.
Configuring Classification Using Port Trust States
This section describes how to classify incoming traffic by using port trust states:
Configuring the Trust State on Ports within the QoS Domain, page 23-18
Configuring the CoS Value for an Interface, page 23-19
Configuring Trusted Boundary, page 23-20
Enabling Pass-Through Mode, page 23-22
Table23-5 Interaction Between Policy Maps and Security ACLs
Policy-Map Conditions
Security-ACL
Conditions Action
When the packet is in profile. Permit specified
packets.
Traffic is forwarded.
When the packet is out of profile and the
out-of-profile action is to mark down the DSCP
value.
Drop specified
packets.
Traffic is dropped.
When the packet is out of profile and the
out-of-profile action is to drop the packet.
Permit specified
packets.
Traffic is dropped.
Drop specified
packets.
Traffic is dropped.