配置思路
流量监管功能是通过QoS命令行实现。本案例中,用户采用固定IP,因此可以通过匹配用户IP地址的方法匹配用户流量,并对其做流量监管。
配置步骤
# 配置ACL规则匹配源IP为10.0.0.2的流量
<H3C> system-view
[H3C] acl number 3001
[H3C-acl-adv-3001] rule permit ip source 10.0.0.2 0
[H3C-acl-adv-3001] quit
# 配置ACL规则匹配目的IP为10.0.0.2的流量
[H3C] acl number 3002
[H3C-acl-adv-3002] rule permit ip destination 10.0.0.2 0
[H3C-acl-adv-3002] quit
# 配置流分类,匹配ACL规则3001,即匹配源IP为10.0.0.2的流量
[H3C] traffic classifier source_hostA
[H3C-classifier-source_hostA] if-match acl 3001
[H3C-classifier-source_hostA] quit
# 配置流分类,匹配ACL规则3002,即匹配目的IP为10.0.0.2的流量
[H3C] traffic classifier destination_hostA
[H3C-classifier-destination_hostA] if-match acl 3002
[H3C-classifier-destination_hostA] quit
# 配置流行为,用于对上行流量进行流量监管,速率为1000kbps
[H3C] traffic behavior uplink
[H3C-behavior-uplink] car cir 1000
[H3C-behavior-uplink] quit
# 配置流行为,用于对下行流量进行流量监管,速率为2000kbps
[H3C] traffic behavior downlink
[H3C-behavior-downlink] car cir 2000
[H3C-behavior-downlink] quit
# 配置QoS策略,用于端口入方向,即用户的上行方向
[H3C] qos policy uplink
[H3C-qospolicy-uplink] classifier source_hostA behavior uplink
[H3C-qospolicy-uplink] quit
# 配置QoS策略,用于端口出方向,即用户的下行方向
[H3C] qos policy downlink
[H3C-qospolicy-downlink] classifier destination_hostA behavior downlink
[H3C-qospolicy-downlink] quit
# 在端口上下发QoS策略,匹配出入方向的流量
[H3C] interface GigabitEthernet 3/0/1
[H3C-GigabitEthernet3/0/1] qos apply policy uplink inbound
[H3C-GigabitEthernet3/0/1] qos apply policy downlink outbound
暂无评论