Ethernet Routing Switch
NN48500-559
Abstract
Table of Contents
List of Tables
List of Figures
Text
Document Updates
Symbols
Conventions
Overview Ethernet Routing Switch 5500 QoS and Filtering
Layer 2 Classifier Elements
Classification
Untrusted Ports
Unrestricted Ports
Statistics
Actions Supported
QoS Flow Chart
Classifier Block Functionality
Filter Functionality
Overall Classification Functionality
7, 15, 31, 63 255, 511, 1025 4095, 8191 32762, or Min =
Port Range Functionality
Policies
Default Policy Drop Action
NN48500-559
Queue Sets
5520-24T-PWRconfig#qos agent buffer large maximum regular
5520-24T-PWRconfig#default qos agent buffer
Egress CoS Queuing
Ethernet Routing Switch 5500 Egress CoS Queuing
CoS
5520-24T-PWRconfig#qos agent queue set
5520-24T-PWRconfig#show qos queue-set-assignment
Egress Queue Recommendations
5520-24T-PWRconfig#default qos agent queue-set
5520-24T-PWRconfig#qos agent reset-default
Bucket Size
Traffic Meter and Shaping
Parameter Description
Actual Bucket Size
Policing Traffic
Actual Bucket Size in Bytes Actual size in bytes Interface
Example
Bucket Size Max burst rate Committed rate Duration MSec
Interface Shaper
Meter Bucket Size and Duration
5530-24TFDconfig#show qos if-shaper port
Hex Decimal
Default Nortel Class of Service
Default Nortel CoS Markings
Binary
Config#qos ip-acl name 1..16 character string ?
QoS Access Lists ACL
ACL Configuration
IP-ACL Configuration
Config#qos l2-acl name 1..16 character string ?
2 L2-ACL Configuration
ACL-Assign Configuration
ACL Configuration Example
5530H-24TFD#show qos ip-acl
Verification
5530H-24TFD#show qos acl-assign
5530H-24TFD#show qos policy
Changing ACL
5500config#no qos acl-assign
5500config#no qos acl-assign 1 port 1/19
5500config#no qos ip-acl
Dhcp Snooping
IP Security Features
Dhcp Snooping Configuration
Dynamic ARP Inspection Configuration
IP Source Guard
IP Source Guard Configuration
Bpdu Filtering
Bpdu Filtering Configuration
QoS Interface Applications
QoS Applications Number of Classifiers Used Feature
ARP Spoofing
Configuration Example
Dhcp Snooping
Dhcp Attacks
10.3 DoS
Bpdu Blocking
ERS5500-48T#show qos if-group
Configuration Steps Policy Configuration
Role Combination
ERS5500-48T#show qos if-assign
IP Element
ERS5500-48Tconfig#qos ip-element 1-64000?
Classification
Adding IP and L2 Element
Adding a Classifier Block
Adding a Classifier
Parameters and variables Description
Meters
Add a New Policy
QoS Action
Configuration Examples
Pre-defined Values
Configure the IP elements
Configuration Example 1 Traffic Meter Using Policies
12.2.1 ERS5500 Configuration Using Policies
Configure the Interface Role Combination
ERS5500 Create the classifier block
Configure Meters
Configure the Classifier Block
Verify the Role Combination
Configure the Policy
Verify Operations
ERS5500 Create the policy
Name m1
Verify Classifier and Classifier Block Configuration
ERS5500-24T#show qos classifier-block
Verify Policy Configuration Verify that the QoS Policy
IP ACL, Dhcp Snooping, ARP Inspection, and Source Guard
12.3.1 ERS5500 Configuration
ERS5500 Add IP address to Vlan 700 and enable Ospf
ERS5500 Enable ARP-Inspection for VLAN’s 110
Verify DHCP-Snooping
ERS5500 Assign the IP-ACL’s to ports
VID
Verify ARP Inspection
Verify IP Source Guard
Verify ACL Configuration
NN48500-559
NN48500-559
ERS5500-24T#show qos acl-assign
TCP Port Range
Configuration Example 3 Port Range Using ACL or Policy
ERS5500 Create IP elements for UDP port range
Configuration Using Policies
Configure the Policies
ERS5500 Remark all other traffic to Bronze
Configuration Using IP-ACL’s
Create Policy
12.5.1 ERS5500 Configuration Using Policies
ERS5500 Assign the L2-ACL’s to ports
12.5.2 ERS5500 Configuration Using IP-ACL’s
ERS5500 Pass all other traffic with standard CoS
12.6.1 ERS5500 Configuration Using Policies
Configuration Example 5 L2 and L3 Classification
ERS5500 Add L2 elements for Vlan 110
Configure Classifier and Classifier Blocks
Dscp Mapping via Un-restricted Port Role
12.7.1 ERS5500 Configuration
Policy Configuration
ACL Configuration
ID ID
View the Queue Assignments
Verify Shape Rate Configuration
Configuration Example 7 Interface Shaping
Enable Shaping on Port
Reference Documentation
Software Baseline
Contact us