QoS Police on 3945 router not working

I am trying to police backup traffic between data centers on a 3945 router.  I want to limit the amount of traffic to 40 Mbps.  I have created a policy and applied on input to the Ethernet WAN facing interface of the router.
Configuration looks like this:
class-map match-any commvault
 match access-group name commvault
policy-map police
 class commvault
  police rate 40000000  burst 20000
   conform-action set-dscp-transmit af13
   exceed-action drop
   violate-action drop
interface GigabitEthernet0/1
service-policy input police
Show policy map interface below.  The problem is that all packets are being marked as conforming even though the byte rate is well above 40 Mbps.  I'm not sure if this is a configuration issue or a bug or something that just isn't supported on this router. 
GigabitEthernet0/1
  Service-policy input: police
    Class-map: commvault (match-any)
      2807844 packets, 225300484 bytes
      30 second offered rate 1162000 bps, drop rate 0000 bps
      Match: access-group name commvault
        2807844 packets, 225300484 bytes
        30 second rate 1162000 bps
      police:
          rate 40000000 bps, burst 20000 bytes, peak-burst 20000 bytes
        conformed 2807844 packets, 225300484 bytes; actions:
          set-dscp-transmit af13
        exceeded 0 packets, 0 bytes; actions:
          drop
        violated 0 packets, 0 bytes; actions:
          drop
        conformed 1162000 bps, exceeded 0000 bps, violated 0000 bps
    Class-map: class-default (match-any)
      8824278 packets, 1864242262 bytes
      30 second offered rate 14071000 bps, drop rate 0000 bps
      Match: any

Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
Where do you see the byte rate (for this class) exceed 40 Mbps?  You have a snapshot stat of that?
You're policing WAN ingress?

Similar Messages

  • Back To My Mac to a Time Capsule through a 3Com Router not working

    I have a Mac Book Pro (10.5.7), Time Capsule (7.4.1), 3Com Office Connect Wireless Router (3CRWDR101A-75), a trial subscription to Mobile Me and a 2.5G iPhone (2.2.1).
    I have been unable to get BTTM from my Mac on a remote wireless connection to my Time Capsule working - hence this post.
    The set up of the Time Capsule was quite straightforward (as I would have expected from Apple) and I quickly established local and remote iCal / Address Book sync between my Mac, www.me.com and my iPhone. I have enabled and am the 2.4 and 5GHz bands on the Time Capsule and the wireless air interface on the 3Com router has been turned off. All of internet and email services on my Mac work well locally and Time Machine work. So far so good.
    However, I am unable to 'see' my Time Capsule in Finder from any WiFi network that is not my home network. When at home I have full access to Time Capsule's disk.
    My 3Com Office Router 3CRWDR101A-75 is not on the list of supported routers (nor is any other 3Com Router) but it does provide UPnP and NAT as required according to Mobile Sync notes including http://support.apple.com/kb/HT1552 and http://support.apple.com/kb/HT1552. Despite my best efforts, I have been unable to find out from Apple's MobileMe support if there are any minimum requirements for any router to work with Back To My Mac so can't check to see if my 3Com router will ever work with BTTM or not.
    Does anyone have any similar experience with setting up a 3Com Office Connect router to work with Back to My Mac?
    Do I need to check / Can I check if my Time Capsule has been registered with the Mobile Me servers?
    Do I need to enable any specific ports on my 3Com Office Connect router?
    Basic settings:
    Time Capsule: green light - all OK
    AirPort Utility>Internet: Connection Sharing: Off (Bridge Mode)
    AirPort Utility>Advanced>Mobile me: account set up
    AirPort Utility>Advanced>IPv6: IPv6 mode = Node, at the request of Apple Mobile Me support
    System Preferences>Mobile Me>BackToMy Mac: On (green light).
    3Com Office Connect Router: DCHP server: On
    3Com Office Connect Router: Firewall level: High (default)
    3Com Office Connect Router: Disable NAT: Off (default)
    3Com Office Connect Router: Enable Universal Plug & Play: On
    3Com Office Connect Router: Enable IPSEC-NAT pass through: ON, at the request of Apple Mobile me support
    Com Office Connect Router: DMZ: enable 1-to-1 NAT: Off (default)
    Any ideas?
    Thanks.

    Quick update on troubleshooting BTTM (or rather Back To My Time Capsule)...
    Surprising;y, no 3Com products listed in http://support.apple.com/kb/TS1304. 3Com tech support stated that no OfficeConnect products have been qualified against BTTM and my specific router does not support IPv6 over IPv4 encapsulation.
    MobileMe support were not able to help, citing the fact that I had an unsupported router.
    I have made no change to my modem/router config since first posted but since an upgrade of my TC to 7.4.2 I have been able to use BTTM with my TC (bridge mode) and my OfficeConnect modem/router (802.11b WiFi disabled).
    I have made limited testing from other remote locations from my MBP and also proved that it worked over a 3G/UMTS connection on the UK's 02 network also
    MobileMe still reporting uPnP / NAT problem on my MBP when working remotely though.
    http://discussions.apple.com/message.jspa?messageID=9733258 confirms that this has been solved and, apart from the anomalous Mobileme status message, I can agree.
    Good news so now do not need to swap out my 3Com router. Also shows that this 3Com product does meet BTTM connectivity requirements.
    Message was edited by: Elise49
    Message was edited by: Elise49

  • Linksys WRT54G Wireless-G Router Not working

    I have a Linksys WRT54G Wireless-G Router and it has worked good for a couple months and yesterday it stopped. When I plug it in all the lights are lit even though there arent any ethernet cables connected and the power light blinks constantly. I tried holding the reset button on the back and it didnt help. Anyone know whats wrong or anything I can try to fix it?

    You need to try again to reset the router to factory defaults.
    To reset your router to factory defaults, use the following procedure:
    1) Power down all computers, the router, and the modem, and unplug them from the wall.
    2) Disconnect all wires from the router.
    3) Power up the router and allow it to fully boot (1-2 minutes).
    4) Press and hold the reset button for 30 seconds, then release it, then let the router reset and reboot (2-3 minutes).
    5) Power down the router.
    6) Connect one computer by wire to port 1 on the router (NOT to the internet port).
    7) Power up the router and allow it to fully boot (1-2 minutes).
    8) Power up the computer (if the computer has a wireless card, make sure it is off).
    9) Try to ping the router. To do this, click the "Start" button > All Programs > Accessories > Command Prompt. A black DOS box will appear. Enter the following: "ping 192.168.1.1" (no quotes), and hit the Enter key. You will see 3 or 4 lines that start either with "Reply from ... " or "Request timed out." If you see "Reply from ...", your computer has found your router.
    10) Open your browser and point it to 192.168.1.1. This will take you to your router's login page. Leave the user name blank, and in the password field, enter "admin" (with no quotes). This will take you to your router setup page. Note the version number of your firmware (usually listed near upper right corner of screen). Exit your browser.
    If you get this far without problems, try the setup disk (or setup the router manually, if you prefer), and see if you can get your router setup and working.
    If you cannot get "Reply from ..." in step 9 above, your router is dead.
    If you get a reply in step 9, but cannot complete step 10, then either your router is dead or the firmware is corrupt. In this case, use the Linksys tftp.exe program to try to reload your router with the latest firmware. After reloading the firmware, repeat the above procedure starting with step 1.
    If you need additional help, please state your ISP, the make and model of your modem, your router's firmware version, and the results of steps 9 and 10. Also, if you get any error messages, copy them exactly and report back.
    Please let me know how things turn out for you.

  • ISE version 1.3 and static route not working

    This command works without any issues with ISE version 1.1 and 1.2:
    ip route 192.168.1.1 255.255.255.255 gateway 127.0.0.1
    However, it does NOT work in ISE version 1.3.  See below:
    ciscoisedev/admin(config)# ip route 192.168.1.1 255.255.255.255 gateway 127.0.0.1
    % Warning: Could not find outgoing interface for gateway 127.0.0.1 while trying to add the route.
    % Error: Error adding static route.
    ciscoisedev/admin(config)#
    Any ideas anyone?

    So it appears that there is no option to lock down access to the shell now that the command that you used to use is no longer valid. What is worse is that there isn't an option to create an ACL in the shell that you could attach to the interface. So I would recommend that you create a defect with Cisco TAC and get this re-added or request that ACL functionality is added. 
    For the GUI (in case you were not already aware of this), you can restrict access from Administration > Admin Access > Settings > Access > IP Access

  • Safari routing not working

    Hello all,
    I have a very strange problem and I'm looking for suggestions. Recently, I tried using my work place VNP which I log into using a web browser. This event seemed to have completely broken safari.
    At first I thought it was my routing table, but when I check it with netstat -ar, it looks ok. Nother weird. My other applications are still working (mail, iChat). Opera works correctly too, but Safari always tells me that I am not connected to the internet. I have tried restarting and Resetting Safari but so far that does not work. I searched my disk using spotlight for all the files that changed today and got rid of the safari related files but this does not work either.
    It's a very strange problem and I'm looking for suggestions on what else to try.
    Thank you in advance.

    You're welcome. Sometimes the little things can be the most confounding.
    Thanks for the and Aloha from Big Island.

  • Wireless router not working

    I have a WRT54G Wireless-G Broadband Router.  I know next to nothing about computers.  The router has worked fine, broadcasting signals to two other computers for over a year.  But suddenly last night it stopped working for one computer, and then 30 minutes later it stopped working for the other.  Neither computer could find the signal.
    I went to the 192.168.1.1 website and found that some settings had changed.  I restored the Network Name (SSID) and the WEP key.  After that, one of the wireless computers could "see" the signal.  But I still can't connect to the internet on either wireless computer.
    Does anyone have any suggestions? 

    What error message you are getting while connecting to the wireless network....?
    Which operating system you are using on the computer...?
    Make sure that you are typing the correct security key on the computer..If you are using WEP then,use Key1 as the security/network key.The security key is case sensitive.
    Message Edited by Wizzard on 02-19-2010 07:13 AM

  • DMVPN per tunnel QOS. show policy-map multipoint not working

    Hi All,
    I have a DMVPN hub which is a 1841 with image c1841-advsecurityk9-mz.151-4.M1.bin .
    I have been using DMVPN and its awesome but now trying to get the QOS sorted out and having issues.
    I have configured the interface like so.
    interface Tunnel1
    ip address 10.255.255.1 255.255.255.0
    no ip redirects
    ip mtu 1400
    ip nhrp authentication xxx
    ip nhrp map multicast dynamic
    ip nhrp map group ADSL1 service-policy output ADSL1
    ip nhrp network-id 1
    ip nhrp redirect
    ip tcp adjust-mss 1360
    no ip split-horizon
    ip ospf 1 area 0
    tunnel source Loopback0
    tunnel mode gre multipoint
    tunnel key 1
    tunnel path-mtu-discovery
    tunnel protection ipsec profile VPN
    end
    policy-map ADSL1
    class class-default
      shape average 1000000
      service-policy Classes
    policy-map Classes
    class Silver
      bandwidth percent 25
      fair-queue
    class Gold
      bandwidth percent 50
      fair-queue
    class Scavanger
      bandwidth percent 5
    class class-default
      fair-queue
    The output of show dmvpn detail shows it has applied the QOS rule.
    NG-SR-WE-RT-2#show dmvpn detail
    Legend: Attrb --> S - Static, D - Dynamic, I - Incomplete
        N - NATed, L - Local, X - No Socket
        # Ent --> Number of NHRP entries with same NBMA peer
        NHS Status: E --> Expecting Replies, R --> Responding, W --> Waiting
        UpDn Time --> Up or Down Time for a Tunnel
    ==========================================================================
    Interface Tunnel1 is up/up, Addr. is 10.255.255.1, VRF ""
       Tunnel Src./Dest. addr: 10.32.0.100/MGRE, Tunnel VRF ""
       Protocol/Transport: "multi-GRE/IP", Protect "VPN"
       Interface State Control: Disabled
    Type:Hub, Total NBMA Peers (v4/v6): 1
    # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb    Target Network
        1  x.x.x.x    10.255.255.2    UP    1d18h    D    10.255.255.2/32
    NHRP group: ADSL1
    Output QoS service-policy applied: ADSL1
    but my router cannot run show policy-map multipoint... it doesnt come up with a tab but i can write it in by hand.  Even when i write it in by hand it outputs blank.
    I cut the ADSL1 shape down to 512k and it didnt take affect so i dont think the qos is working at all.
    Is my feature set too low?
    Cheers,
    Simon

    Ray,
    There could be multiple reasons for it not to function, the config on hub seems just fine, we'd need to inspect the spokes and check (most likely) in debugs if correct group is being sent from spoke.
    Also coexistance of other service-policy etc etc.
    The feature is quite simple (some level of simplification), spoke says he is in group X when registering, hub assigns this NHRP mapping a service-policy.
    M.

  • Per-Tunnel QoS on a DMVPN Tunnel Not Working.

    Hello, I am trying to get per-Tunnel QoS working on one of my Hub tunnels, and believe to have the configurations correctly, but when I do "show ip nhrp group-map" I get NONE. I am running a MPLS-VPN network and this router has multiple DMVPN Tunnels with different VRFs. I am not running QoS on the other tunnels.
    router#show ip nhrp group-map
    Interface: Tunnel1
    NHRP group: testgroup
      QoS policy: test-QoS
      Tunnels using the QoS policy: None
    here is my config
    interface Tunnel1
    ip vrf forwarding test
    ip address 172.16.1.1 255.255.255.240
    no ip redirects
    ip mtu 1376
    ip nhrp authentication test
    ip nhrp map multicast dynamic
    ip nhrp map group testgroup service-policy output TEST-QoS
    ip nhrp network-id #####
    ip tcp adjust-mss 1200
    load-interval 30
    tunnel source Loopback1
    tunnel mode gre multipoint
    tunnel key #####
    tunnel vrf test_internet
    tunnel protection ipsec profile IPSECPROFILE shared
    Router Version
    (C7200-ADVENTERPRISEK9-M), Version 15.0(1)M3
    I understand that I could do qos pre-classify in the tunnel and then do a service policy on the physical interface, but the question I have is why does it say " Tunnels using the QoS policy: None " when I configured a qos policy on the tunnel interface? Is this a bug?
    Thank you for your help!

    Ray,
    There could be multiple reasons for it not to function, the config on hub seems just fine, we'd need to inspect the spokes and check (most likely) in debugs if correct group is being sent from spoke.
    Also coexistance of other service-policy etc etc.
    The feature is quite simple (some level of simplification), spoke says he is in group X when registering, hub assigns this NHRP mapping a service-policy.
    M.

  • Wrt54g v8 router not working

    I am trying to use the wrt54g router.  I have spent hours and hours on the phone with linksys, and finally got it to connect to my dsl.  Now when I go to the internet, the msn page will come up, but if you try to go anywhere it sits in limbo.  Maybe if I left it overnight it would come up!  My dsl works fine if I plug it directly into the computer and not through the router.  The dsl is a msn broadband dsl 1000, through qwest.  Any ideas?

    connect the computer to the router's port#1 .. access the router using http://192.168.1.1 .. the default password is admin
    on the ui , change the "internet connection type" to PPPoE. Enter the username and password as provided by the ISP ..
    click on the "mac add clone" subtab , enable it and click clone..save the settings and do a power cycle...
    connect the modem to the router's internet port..do a power cycle..check whether it connects to the internet..

  • Dual nat instance in an router (not working)

    Hi Guys,
    I'm having a problem w/ the design i'm currently working on. As you can see in the diagram below, I was trying to somehow perform load balancing on WAN links. What I'm trying to do is basically for all VLAN 1 users to use the WAN 1 link as their primary wan connection while VLAN 2 users must use WAN 2 link as their primary wan connection. To achieve this, I've configure a PBR on each subinterfaces on my router indicating that VLAN 1 subnet must use the WAN1 as next-hop and VLAN 2 subnet must use WAN2 as next hop for their respective WAN traffics.
    In relationship to my PBR configurations, I've also included "track" command to monitor whether each WAN link still active. Everything works fine until I've defined two "ip nat inside" command on my router. I noticed that only one vlan subnet could communicate on WAN. I don't know if there's an effect for using two NAT instance on the router.
    Hope you could help me on this.
    Thank you so much
    Rex

    A lot of the 960's don't have 2 DVI's. However most have an additional HDMI and DisplayPort. I recommend you get an adapter from amazon or something. Just make sure that it will convert HDMI or DP to DVI. Usually amazon products have a good amount
    of questions already answered by buyers.
    Interesting that they'd go that route, I guess I just assumed since my 760 has two.
    I've set up dual monitors using one DVI and one HDMI before, but I ran into issues with screen sizing. Despite having two identical monitors set at the same resolution the mouse would not transmit over to the second monitor at the same height as it was on
    the first, so I had to buy an adapter like Joshua suggested.

  • Dynamic Routing Not Working

    I'm attempting to use dynamic routing (Dynamic Routing Action) to route to another proxy service and I keep getting "BEA-382000: Error preparing message for dispatch".
    I'm using a lookup table:
    <routingTable>
    <route>
    <relative-uri>/destination_1</relative-uri>
    <route-to>DestinationOne</route-to>
    </route>
    <route>
    <relative-uri>/destination_2</relative-uri>
    <route-to>DestinationTwo</route-to>
    </route>
    </routingTable>
    "DestinationOne" and "DestinationTwo" are local protocol proxy services that reside in two different projects.
    To get the correct route-to value, my XQuery statement is:
    routingTable/route/route-to[../relative-uri='{relative_uri}']
    and I know it works.
    At this point, the first proxy service (the one that does the routing) does nothing but use content from the $inbound variable to lookup the route-to information.
    What am I missing?
    Many thanks,
    -Mark

    We do this often.
    I'm sure it can happen in other ways, but I see the error you're describing commonly in two scenarios:
    1. An error occurred in the second proxy but you don't have an error-handler on that proxy (I've found it really helps to make sure there is an error handler on every proxy that at least logs the $fault and then does Reply with Success, otherwise ALSB sometimes loses the fault details). I think I usually get a BEA-38000 in that case, not a 38200, but off the top of my head I'm not sure.
    2. If an AnySOAP proxy is calling an AnyXml proxy, I get this error. Recently we switched out endpoint to AnySOAP, and I had to go through and recreate all of the proxies to AnySOAP because previously they'd been AnyXml. Even adding error-handling to every possible level didn't give me any better details, I just happened to try the Any SOAP switch on one proxy and learned it fixed the error.
    Hope that helps you track it down, at least there are some examples of what causes this error.
    Meghan

  • HP Deskjet 1050 J410 scanning via router not working

    Hi all,
    I have my printer connected to an Apple Airport Express via USB. Printing via wifi with my laptop works just fine but scanning doesn't work. When I try to scan via my laptop, I get a message that connection to the scanner is not possible. I've looked up port forwarding but don't think that could be the issue, since printing is working fine. Any ideas?
    Thanks!
    Thomas

    Connecting the printer to the router by USB is not a supported configuration.  The problem is, in order to scan, you need the software, and there is no way to install the software on the router and so you cannnot scan.  You might be able to scan to an SD card as a work around but I doubt you are going to find a solution to this problem.  I hope that helps.
    Mike
    Say "Thanks" by clicking the Kudos Star in the post that helped you.
    I am an HP employee.

  • Wireless router not working after Windows update

    I have a WRT54G V.5 wireless router. Windows Vista Home Premium did an auto update. Now wired connection works, wireless does not. Asks for key, but when entered nothing happens. Diagnosis states action was canceled. I have disabled and enabled, does not fix. Any help will be appreciated! 
    Solved!
    Go to Solution.

    Take not of the Wireless Settings(SSID and WEP/WPA Key) on your Router...
    To know the Wireless Settings follow this link
    Once you know the Wireless Settings attempt to connect to your Wireless Network...
    XP :
    Click on Start and goto the Control Panel and double click on Network Connections, right click on Wireless Network Connection and click on Properties.
    Now on this window, click on the second tab Wireless Network and give a check mark on "Use windows to configure my wireless" and then remove all the network names present in the Preferred Networks Window. Then click on OK...
    Right click on the Wireless Network Connection again and click on View Available Wireless Networks and try to re-connect to your network...
    Now it will give you the opportunity to put the network/wep key, make sure you enter the correct network key and confirm it...
    It will connect...
    Vista :
    Click Start >> Control Panel >> Network and Sharing Center >> Manage Wireless Networks, here remove all the networks present and close the Window...
    Click on Connect to a Network and try to re-connect to your Network, it should ask for your Network Key/Password, enter the correct password/network key and click Connect...
    It should connect...Once you are connected you should restart the computer, it should connect to Internet...

  • E1200 router not working -- Error 3005 (and manual network not connecting)

    I'm trying to set up a new E1200 N300 Monitor, and am not having any luck. Using the Cisco Connect program ends in an error during the "Validating connection" step every time, telling me:
    Error: 3005
    An HNAP call to the device failed because the HTTP connection was broken.
    (If it's relevant, the serioal number, connection type, and IP address (WAN) all come up as "unknown" in the error details).
    I am able to set up the router manually via the web browser access. I can name the wifi network, set up the security, and even see and authenticate to the network from my devices, however, no internet connection is available when connected. (The internet connection itself is good -- when I move the incoming cable from the router to the computer, I instantly have perfect access -- thus this post) 
    I've also tried all the basic steps of reset and restarting everything involved multiple times, but I always end with the same result -- 3005 error in the setup app, and then a manually-configured wifi network that appears to be working and can authenticate devices, but does not provide any internet connection.
    I'm at a loss at this point -- does anyone here have any advice? Thanks a lot for your time and input.
    -e.
    Solved!
    Go to Solution.

    What type of internet connection do you have?
    Example:
    PPPoe
    Cable Modem
    ADSL
    Please remember to Kudo those that help you.
    Linksys
    Communities Technical Support

  • Using usb as serial connecting to cisco router not working

    Tried using ZOC and securecrt and both shows only /dev/tty-Bluetooth.....
    any ideas how can I use USB as serial connection to router?

    Hi and welcome to the forums!
    GREAT FIRST POST!! Very clear and specific. You don't know how rare that is
    Is the laptop in a docking bay?
    Content "encryption" meaning Content protection is turned off, right?
    Are you able to backup and sync with the Desktop software?
    Do you have the correct folders on the card?
    Blackberry, music, ringtones, pictures, videos, voice notes?
    (blackberry has to be first).
    Last one, how did you format the card?
    Thanks
    Update device drivers manually:
    http://www.blackberry.com/btsc/search.do?cmd=displ​ayKC&docType=kc&externalId=KB13336&sliceId=SAL_Pub​...
    Message Edited by Bifocals on 11-19-2008 08:36 PM
    Click Accept as Solution for posts that have solved your issue(s)!
    Be sure to click Like! for those who have helped you.
    Install BlackBerry Protect it's a free application designed to help find your lost BlackBerry smartphone, and keep the information on it secure.

Maybe you are looking for

  • DVD's from my DVD/VHS Recorder are not sharp/ Why?

    Hello! I have a 2GHz Intel Core 2 Duo iMac that works perfectly. What I want to know is why my DVD-R's made on my DVD/VHS Recorder look grainy with low sound on my iMac but look great on any regular DVD player and television. Does anybody know why th

  • Blob filename

    i've a table with a blob-column i use webutil to save the object to the client. but how can i get the original filename of the object? a.e the name of the presentation (when it was uploaded) stored in the db (document.ppt). another question is: how c

  • Recording from tv using n95

    hy there, i wondering is there any chance to record tv programs while n95 connected via tv cable ? Nokia N95 v.20.0.15 + 2 Gb microS + RotateMe beta7 + Nokmote beta1+ ShutUp beta1

  • When I click update on Itunes to update my IPod Touch it says an error occured.

    When I update my Ipod it says that an error has occured. It has done that twice.

  • Image does not display on Webi/Information Analyzer report BO XI 4.O

    In Information Analyzer ( Webi ) I am using BO XI 4.0 ramp up version. I have create one report with image on it. I moved the image to image directory on BO server . While creating the report I am able to see the image fine. However when I call the r