Explains data plane policing concepts and provides guidance for controlling bandwidth and marking or dropping excessive traffic on Layer 2 interfaces, Layer 3 interfaces, and endpoint groups.
This chapter contains the following sections:
Data plane policing
Data plane policing (DPP) controls ingress and egress bandwidth on Cisco ACI fabric access interfaces by marking or dropping traffic that exceeds configured rates.
Guidelines and limitations for data plane policing
Review the supported data plane policing modes, actions, statistics, platforms, and feature combinations.
Configure data plane policing for a Layer 2 interface by using the GUI
Create a data plane policing (DPP) policy and configure its traffic rates, policing actions, and sharing mode for a Layer 2 interface.
Configure data plane policing for a Layer 3 interface by using the GUI
Create an ingress data plane policing (DPP) policy and apply it to a routed interface, switched virtual interface, or routed subinterface.
Configuring Data Plane Policing Using the REST API
Describes how to configure data plane policing for Layer 2 and Layer 3 traffic using the REST API. Provides XML configuration examples for both ingress and egress traffic on leaf switches to help users enforce traffic policies.
Configure data plane policing by using the NX-OS-style CLI
Configure and verify data plane policing (DPP) policies for Layer 2 and Layer 3 interfaces by using the NX-OS-style CLI.
Data plane policing at the endpoint group level
Data plane policing (DPP) limits traffic from endpoint group (EPG) members on each leaf switch where the EPG is deployed.