super-vlan下使用traffic policy是否可以生效
问题描述
traffic classifier temp operator or precedence 85
if-match any
traffic behavior temp
statistic enable
remark dscp af23
traffic policy temp
classifier temp behavior temp
vlan 52
description Internet_VRRP_2
aggregate-vlan
access-vlan 2250 to 2499
traffic-policy temp inbound
#
interface GigabitEthernet1/0/0
description To sw-sv-1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 99 1000 1050 1100 1110 1120 1500 to 1749 1951 to 1952 2000 to 2999 3500 to 3999
port-mirroring to observe-port 1 both
client1(213.111.80.9/20)---(1/0/0)S9300(1/0/1 )---Client2(213.111.127.66)
1.确认路由:
213.111.80.0/20 Direct 0 0 D 213.111.80.1 Vlanif52
2.通过对S9300 1/0/0和1/0/1的报文分析发现DSCP值仍然是Default,没有被remark为af23.(见附件中的报文分析)
3.查看super vlan下的流统计结果,发现没有匹配到的记录。
>disp traffic policy statistics vlan 52 inbound verbose classifier-base
Vlan: 52
Traffic policy inbound: temp
Rule number: 1
Current status: OK!
Classifier: temp operator or
Behavior: temp
Board : 1
Item Packets Bytes
---------------------------------------------------------------------
Matched 0 0
+--Passed 0 0
+--Dropped 0 0
+--Filter 0 0
+--URPF - -
+--CAR
告警信息
处理过程
2.查看配置无问题,报文分析DSCP值没有被remark,确认策略没有生效;
3.咨询了研发:在super-vlan上应用策略,只有vlan-id等于super vlan才会匹配,access vlan不会匹配的.(策略是在vlan52上应用的,规则匹配的条件是vlan-id为52,而用户的请求报文的vlan-id为2251,所以无法匹配.)
解决办法:
在流分类中匹配所有的access vlan ID,将流策略应用在接口下(不是super-vlan).