1號口級聯端口,連接一根8兆的電信線路;
2、3、4、5號口,限制每個接口的上、下行帶寬最大是2兆;
詳細配置如下:
----------------------------------------------------------------------------------------
class-map match-all user1-up
match access-group 1
class-map match-all user3-up
match access-group 3
class-map match-all user2-up
match access-group 2
class-map match-all user4-up
match access-group 4
class-map match-all user4-down
match access-group 104
class-map match-all user2-down
match access-group 102
class-map match-all user3-down
match access-group 103
class-map match-all user1-down
match access-group 101
!
!
policy-map user1-up
class user1-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user3-up
class user3-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user2-up
class user2-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user4-up
class user4-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user-down
class user1-down
police 2000000 1000000 exceed-action drop
trust dscp
class user2-down
police 2000000 1000000 exceed-action drop
trust dscp
class user3-down
police 2000000 1000000 exceed-action drop
trust dscp
class user4-down
police 2000000 1000000 exceed-action drop
trust dscp
!
interface FastEthernet0/1
spanning-tree bpdufilter enable
service-policy input user-down
!
interface FastEthernet0/2
service-policy input user1-up
!
interface FastEthernet0/3
service-policy input user2-up
!
interface FastEthernet0/4
service-policy input user3-up
!
interface FastEthernet0/5
service-policy input user4-up
!
match access-group 1
class-map match-all user3-up
match access-group 3
class-map match-all user2-up
match access-group 2
class-map match-all user4-up
match access-group 4
class-map match-all user4-down
match access-group 104
class-map match-all user2-down
match access-group 102
class-map match-all user3-down
match access-group 103
class-map match-all user1-down
match access-group 101
!
!
policy-map user1-up
class user1-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user3-up
class user3-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user2-up
class user2-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user4-up
class user4-up
police 2000000 1000000 exceed-action drop
trust dscp
policy-map user-down
class user1-down
police 2000000 1000000 exceed-action drop
trust dscp
class user2-down
police 2000000 1000000 exceed-action drop
trust dscp
class user3-down
police 2000000 1000000 exceed-action drop
trust dscp
class user4-down
police 2000000 1000000 exceed-action drop
trust dscp
!
interface FastEthernet0/1
spanning-tree bpdufilter enable
service-policy input user-down
!
interface FastEthernet0/2
service-policy input user1-up
!
interface FastEthernet0/3
service-policy input user2-up
!
interface FastEthernet0/4
service-policy input user3-up
!
interface FastEthernet0/5
service-policy input user4-up
!
!
access-list 1 permit *.*.*.*
access-list 2 permit *.*.*.*
access-list 3 permit *.*.*.*
access-list 1 permit *.*.*.*
access-list 2 permit *.*.*.*
access-list 3 permit *.*.*.*
access-list 4 permit *.*.*.*
access-list 101 permit ip any host *.*.*.*
access-list 102 permit ip any host *.*.*.*
access-list 103 permit ip any host *.*.*.*
access-list 104 permit ip any host *.*.*.*
!
access-list 101 permit ip any host *.*.*.*
access-list 102 permit ip any host *.*.*.*
access-list 103 permit ip any host *.*.*.*
access-list 104 permit ip any host *.*.*.*
!
---------------------------------------------------------------------------------