164 Chapter 6: QoS Features Available on the Catalyst 2950 and 3550 Family of Switches
The class map MATCH_LIST defines a class map with several classification matching
rules. Because the class map uses the match-any option, matching any of the three match
statements results in policy map executing the class actions. The other matching option,
match-all, configures the switch to subject the packet to all the match statements in order
to enact on the policy map class actions.
Furthermore, the class map defines three matching rules. For the switch to execute the class
actions in the policy map, a packet must match ACL 100, have an IP precedence value of 5,
or have an IP DSCP value of 35. Otherwise, the switch does not execute the class actions
for the packet. Because the switch applies the policy map on ingress, the switch performs
the matching operation on all ingress frames on GigabitEthernet0/1.
For packets that match the classification rules in the class map, the switch executes the class
actions defined in the policy map. In Example 6-15, the switch rate limits this traffic by
dropping frames above the defined rate of 1.0 Mbps and sets the internal DSCP value to 55.
Chapter 5 provides additional configuration information on class maps and policy maps.
The “Traffic-Rate Policing” section later in this chapter discusses the rate policer in
Example 6-15.
Ingress and Egress Policing
Ingress policing logically refers to applying a set of class actions such as trusting, marking,
or rate policing to specific packets as the switch receives packets inbound. Ingress policing
logically occurs when a switch receives a packet, but actually occurs later in packet
processing on Catalyst switches. Nevertheless, the logical concept of ingress policing is
applying class actions to received packets. Egress policing applies a set of class actions on
transmit; however, this feature is not found on all Catalyst switches. At the time of publi-
cation, only the Catalyst 3550 Family and 4000 IOS Family of switches support egress
policing and the Catalyst 3550 Family of switches supports only traffic-rate policers for
egress policing.
police 1000000 8000 exceed-action drop
set ip dscp 55
!
(text deleted)
interface GigabitEthernet0/1
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
service-policy input RATE_MARK
(text deleted)
access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.1.0 0.0.0.255
(text deleted)
!
end
Example 6-15 Sample Class Map and Policy Map Configuration (Continued)