3com 5500G ユーザーズマニュアル

ページ / 336
222
C
HAPTER
 23: Q
O
S/Q
O
S P
ROFILE
 C
ONFIGURATION
 G
UIDE
rule 1 permit TCP source 192.168.0.1 0 destination-port eq www time-range tr2
#
interface Ethernet1/0/1
traffic-redirect inbound ip-group 3000 rule 0 interface Ethernet1/0/2
traffic-statistic inbound ip-group 3000 rule 1
#
time-range tr2 00:00 to 08:30 working-day
time-range tr2 18:00 to 24:00 working-day
time-range tr2 00:00 to 24:00 off-day
time-range tr1 08:30 to 18:00 working-day
Precautions
Note that:
The ACL rules configured for traffic classification must be permit statements.
When redirecting a packet, the switch processes the packet with the 
forwarding mechanism instead of leaving it intact.
With traffic redirection configured, the switch does not forward the packets to 
be redirected as usual.
The packets received on the destination port for redirection are tagged.
Configuring QoS 
Profile
Network Diagram
Figure 65   Network diagram for QoS profile configuration
 
Networking and
Configuration
Requirements
A company uses a switch (a Switch 5500 in this example) to interconnect all the 
departments. The 802.1x protocol is used to authenticate the users and control 
user access to the network resources. A user named someone in the test.net 
domain is connected to Ethernet 1/0/1 of the switch. Its password is hello.
Configure a QoS profile to limit the outgoing IP traffic rate of the user someone 
to 128 kbps after the user passes the 802.1x authentication, and drop the packets 
exceeding the rate limit.
User
Switch
Network
AAA Server
Eth1/0/1