Configuring a Connection Parameter Map for TCP/IP Normalization and Termination
Configuring Rate Limits for a Policy Map
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
4-8
Chapter 4
The ACE allows you to limit the connection rate and the bandwidth rate of a
policy map. The connection rate is the number of connections per second that
match the policy. The bandwidth rate is the number of bytes per second that match
the policy. The ACE applies these rate limits to each class map that you associate
with the policy at the virtual server level.
When the connection-rate limit or the bandwidth-rate limit is reached, the ACE
blocks any further traffic that matches that policy until the connection rate or
bandwidth rate drops below the configured limit. By default, the ACE does not
limit the connection rate or the bandwidth rate of a policy.
You can also limit the connection rate and the bandwidth rate of a real server in a
server farm. For details, see the Cisco 4700 Series Application Control Engine
Appliance Server Load-Balancing Configuration Guide.
To limit the connection rate or the bandwidth rate of a policy, use the rate-limit
command in parameter map connection configuration mode. The syntax of this
command is as follows:
rate-limit {connection number1 | bandwidth number2}
The keywords and arguments are as follows:
connection number1—Specifies the connection-rate limit for a policy in
•
connections per second. Enter an integer from 0 to 350000. There is no
default value.
bandwidth number2—Specifies the bandwidth-rate limit for a policy in bytes
•
per second. Enter an integer from 0 to 300000000. There is no default value.
For example, to limit the connection rate of a policy to 100000 connections per
second, enter:
host1/Admin(config)# parameter-map type connection RATE-LIMIT
host1/Admin(config-parammap-conn)# rate-limit connection 100000
To return the behavior of the ACE to the default of not limiting the policy
connection rate, enter:
host1/Admin(config-parammap-conn)# no rate-limit connection 100000
For example, to limit the policy bandwidth rate to 5000000 bytes per second,
enter:
Configuring TCP/IP Normalization and IP Reassembly Parameters
OL-16202-01