Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configure data plane policing for a Layer 2 interface by using the GUI

Want to summarize with AI?

Log in

Create a data plane policing (DPP) policy and configure its traffic rates, policing actions, and sharing mode for a Layer 2 interface.


Before you begin

Identify the interface policy group and interface profile that are associated with the Layer 2 interface.

To apply the DPP policy, add it to an interface policy group and associate the policy group with an interface profile.

Procedure

  1. On the menu bar, choose Fabric > Access Policies .

  2. In the Navigation pane, choose Policies > Interface > Data Plane Policing .

  3. Right-click Data Plane Policing and choose Create a Data Plane Policing Policy .

  4. In the Create a Data Plane Policing Policy dialog box, enter a policy name in the Name field.

  5. For Administrative State , choose Enabled .

  6. For Policer Mode , choose Bit Policer or Packet Policer .

  7. For Type , choose 1 Rate 2 Color or 2 Rate 3 Color .

    Switch models with names that end in -EX or -FX, such as the N9K-C93180YC-FX, and later switch models do not support 2 Rate 3 Color.

    Note

    Selecting 2 Rate 3 Color on an unsupported switch generates a fault.

  8. For Conform Action , choose the action to apply to conforming traffic.

    • Drop —Drops conforming packets.

    • Mark —Marks the QoS fields of conforming packets.

    • Transmit —Transmits conforming packets.

    Note

    The marking configuration in the following step does not apply to egress DPP.

  9. If you chose Mark for Conform Action , configure the marking values.

    1. For Conform mark CoS , enter the class of service (CoS) value for conforming packets.
    2. For Conform mark dscp , enter the differentiated services code point (DSCP) value for conforming packets.
  10. If you chose 2 Rate 3 Color for Type , choose the action to apply to exceeding traffic from Exceed Action .

    • Drop —Drops exceeding packets.

    • Mark —Marks the QoS fields of exceeding packets.

    • Transmit —Transmits exceeding packets.

  11. If you chose Mark for Exceed Action , configure the marking values.

    1. For Exceed mark CoS , enter the CoS value for exceeding packets.
    2. For Exceed mark dscp , enter the DSCP value for exceeding packets.
  12. For Violate Action , choose the action to apply to violating traffic.

    • Drop —Drops violating packets.

    • Mark —Marks the QoS fields of violating packets.

    • Transmit —Transmits violating packets.

  13. If you chose Mark for Violate Action , configure the marking values.

    1. For Violate mark CoS , enter the CoS value for violating packets.
    2. For Violate mark dscp , enter the DSCP value for violating packets.
  14. For Sharing Mode , choose Shared Policer .

    Shared Policer applies the same policing parameters to multiple interfaces. Layer 2 interfaces do not support Dedicated Policer mode.

  15. For Rate , enter the permitted traffic rate and choose the appropriate unit.

  16. For Burst , enter the permitted burst allowance and choose the appropriate unit.

  17. If you chose 2 Rate 3 Color for Type , configure the peak rate and excessive burst values.

    1. For Peak Rate , enter the peak information rate and choose the appropriate unit.
    2. For Excessive Burst , enter the maximum burst size before traffic exceeds the peak information rate, and choose the appropriate unit.
  18. Click Submit .

The DPP policy is created and is available for assignment to a Layer 2 interface policy group.

What to do next

Add the DPP policy to the appropriate interface policy group, and associate the policy group with the interface profile for the Layer 2 interface.