Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configuring Data Plane Policing Using the REST API

Want to summarize with AI?

Log in

Describes how to configure data plane policing for Layer 2 and Layer 3 traffic using the REST API. Provides XML configuration examples for both ingress and egress traffic on leaf switches to help users enforce traffic policies.


Configure policing for Layer 2 and Layer 3 traffic on leaf switches using the REST API by applying XML configuration examples for both ingress and egress directions.

Policing Layer 2 Traffic (Ingress and Egress)

To police the Layer 2 traffic coming in to the leaf switch:

<!--  api/node/mo/uni/.xml  -->
				<infraInfra>
				<qosDppPol name="infradpp5" burst="2000" rate="2000" be="400" sharingMode="shared"/>
				<!--
				List of nodes. Contains leaf selectors. Each leaf selector contains list of node blocks
				-->
				<infraNodeP name="leaf1">
				<infraLeafS name="leaf1" type="range">
				<infraNodeBlk name="leaf1" from_="101" to_="101"/>
				</infraLeafS>
				<infraRsAccPortP tDn="uni/infra/accportprof-portselector1"/>
				</infraNodeP>
				<!--
				PortP contains port selectors. Each port selector contains list of ports. It
				also has association to port group policies 
				-->
				<infraAccPortP name="portselector1">
				<infraHPortS name="pselc" type="range">
				<infraPortBlk name="blk" fromCard="1" toCard="1" fromPort="48" toPort="49"></infraPortBlk>
				<infraRsAccBaseGrp tDn="uni/infra/funcprof/accportgrp-portSet2"/>
				</infraHPortS>
				</infraAccPortP>
				<!--  FuncP contains access bundle group policies  -->
				<infraFuncP>
				<infraAccPortGrp name="portSet2">
				<infraRsQosIngressDppIfPol tnQosDppPolName="infradpp5"/>
				</infraAccPortGrp>
				</infraFuncP>
				</infraInfra>
			

To police the Layer 2 traffic going out of the leaf switch:

<!--  api/node/mo/uni/.xml  -->
				<infraInfra>
				<qosDppPol name="infradpp2" burst="4000" rate="4000"/>
				<!--
				List of nodes. Contains leaf selectors. Each leaf selector contains list of node blocks
				-->
				<infraNodeP name="leaf1">
				<infraLeafS name="leaf1" type="range">
				<infraNodeBlk name="leaf1" from_="101" to_="101"/>
				</infraLeafS>
				<infraRsAccPortP tDn="uni/infra/accportprof-portselector2"/>
				</infraNodeP>
				<!--
				PortP contains port selectors. Each port selector contains list of ports. It
				also has association to port group policies 
				-->
				<infraAccPortP name="portselector2">
				<infraHPortS name="pselc" type="range">
				<infraPortBlk name="blk" fromCard="1" toCard="1" fromPort="37" toPort="38"></infraPortBlk>
				<infraRsAccBaseGrp tDn="uni/infra/funcprof/accportgrp-portSet2"/>
				</infraHPortS>
				</infraAccPortP>
				<!--  FuncP contains access bundle group policies  -->
				<infraFuncP>
				<infraAccPortGrp name="portSet2">
				<infraRsQosEgressDppIfPol tnQosDppPolName="infradpp2"/>
				</infraAccPortGrp>
				</infraFuncP>
				</infraInfra>

Policing Layer 3 Traffic (Ingress and Egress)

To police the Layer 3 traffic coming in to the leaf switch:

<!--  api/node/mo/uni/.xml  -->
				<fvTenant name="dppTenant">
				<qosDppPol name="gmeo" burst="2000" rate="2000"/>
				<l3extOut name="Outside">
				<l3extInstP name="extroute"/>
				<l3extLNodeP name="borderLeaf">
				<l3extRsNodeL3OutAtt tDn="topology/pod-1/node-101" rtrId="10.0.0.1">
				<ipRouteP ip="0.0.0.0">
				<ipNexthopP nhAddr="192.168.62.2"/>
				</ipRouteP>
				</l3extRsNodeL3OutAtt>
				<l3extLIfP name="portProfile">
				<l3extRsPathL3OutAtt addr="192.168.40.1/30" ifInstT="l3-port" tDn="topology/pod-1/paths-101/pathep-[eth1/40]"/>
				<l3extRsPathL3OutAtt addr="192.168.41.1/30" ifInstT="l3-port" tDn="topology/pod-1/paths-101/pathep-[eth1/41]"/>
				<l3extRsIngressQosDppPol tnQosDppPolName="gmeo"/>
				</l3extLIfP>
				</l3extLNodeP>
				</l3extOut>
				</fvTenant>

To police the Layer 3 traffic going out of the leaf switch:

<!--  api/node/mo/uni/.xml  -->
				<fvTenant name="dppTenant">
				<qosDppPol name="gmeo" burst="2000" rate="2000"/>
				<l3extOut name="Outside">
				<l3extInstP name="extroute"/>
				<l3extLNodeP name="borderLeaf">
				<l3extRsNodeL3OutAtt tDn="topology/pod-1/node-101" rtrId="10.0.0.1">
				<ipRouteP ip="0.0.0.0">
				<ipNexthopP nhAddr="192.168.62.2"/>
				</ipRouteP>
				</l3extRsNodeL3OutAtt>
				<l3extLIfP name="portProfile">
				<l3extRsPathL3OutAtt addr="192.168.40.1/30" ifInstT="l3-port" tDn="topology/pod-1/paths-101/pathep-[eth1/40]"/>
				<l3extRsPathL3OutAtt addr="192.168.41.1/30" ifInstT="l3-port" tDn="topology/pod-1/paths-101/pathep-[eth1/41]"/>
				<l3extRsEgressQosDppPol tnQosDppPolName="gmeo"/>
				</l3extLIfP>
				</l3extLNodeP>
				</l3extOut>
				</fvTenant>