Another way buat rate-limiting dari cara sebelumnya. Kali ini dengan menggunakan class-map:
#1 buat access-list
access-list 115 remark Rate limit client
access-list 115 remark ip exclude from rate-limit
access-list 115 deny tcp host 10.11.129.16 any
access-list 115 deny tcp host 10.11.129.7 any
access-list 115 deny tcp host 10.11.129.90 any
access-list 115 deny tcp 172.16.1.0 255.255.255.248 any
access-list 115 remark protocol yang dirate-limit
access-list 115 permit tcp any any eq www
access-list 115 permit tcp any any eq ftp
access-list 115 permit tcp any any eq 443
#2 class-map
class-map match-all rate-limit-client
match access-group 115
policy-map rate-limit-client
class rate-limit-client
police 50000 bps 50000 byte conform-action transmit exceed-action drop
#3 assign pada interface yang sesuai
interface GigabitEthernet0/0.7
service-policy input rate-limit-client
service-policy output rate-limit-client
Adopsi dari artikel Cisco IOS – rate limiting a server. Bisa digunakan nggak ya? belum coba soale hihihiā¦
Technorati Tags: cisco,rate-limit,class-map






Komentar terakhir