QoS on SVI interface

Unanswered Question
Dec 15th, 2008

Can not configure Qos for SVI interface.


Class Map match-any class-default (id 0)

Match any

Class Map match-any cl-voice (id 1)

Match access-group 110

Class Map match-all cl-input (id 2)

Match input-interface GigabitEthernet1/0/1


Extended IP access list 110

10 permit ip any

20 permit ip any

30 permit ip any


Policy Map POL-VOICE

Class cl-input

police 10000000 100000 exceed-action drop


Class cl-voice

set dscp 31

service-policy POL-VOICE


interface Vlan120

ip address

service-policy input POL-PARENT

Networks in the access list are Ip phone networks. Need to offer a rate limit to those networks.

When executing sh policy-map interface vlan 120:


Service-policy input: POL-PARENT

Class-map: cl-voice (match-any)

0 packets, 0 bytes

5 minute offered rate 0 bps, drop rate 0 bps

Match: access-group 110

Service-policy : POL-VOICE

Class-map: cl-input (match-all)

0 packets, 0 bytes

5 minute offered rate 0 bps, drop rate 0 bps

Match: input-interface GigabitEthernet1/0/1

Class-map: class-default (match-any)

0 packets, 0 bytes

5 minute offered rate 0 bps, drop rate 0 bps

Match: any

Class-map: class-default (match-any)

226 packets, 15016 bytes

5 minute offered rate 0 bps, drop rate 0 bps

Match: any

Interface gigabit 1/0/1 is an ingress port from those networks in this case

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Giuseppe Larosa Tue, 12/16/2008 - 01:53

Hello Faz,

try to avoid to use hierarchical policy maps to see what happens

Hope to help


Marwan ALshawi Tue, 12/16/2008 - 03:06

are you using 3560 switch?

simple question

do u have qos enabled with

mls qos command

Marwan ALshawi Mon, 12/22/2008 - 02:13

for ACL 110 can you make one line instead of 3 lines and try it

also make it match ip any to any and try it as well

good luck

fgasimzade Mon, 12/22/2008 - 03:27

I made it match ip any any - it worked fine. However, when configuring various networks nothing works

Marwan ALshawi Mon, 12/22/2008 - 03:32

then my suspect was almost right

i am happy it at least worked even not fully

i think this tied of policing with HQ policies support one line ACL

just put a supper address for voice vlan in one line acl only and let me know

like /23

good luck

fgasimzade Mon, 12/22/2008 - 03:41

I deleted all networks from access list and left only one - no results, I am afraid. However, with match ip any any it still works fine. I am really confused

Marwan ALshawi Mon, 12/22/2008 - 03:48

ok as long as u matching voip traffic make ur acl or class map based on cos or dscp

like match ip any any dscp ef

like this

in this case u will make it better and get it work for that voip traffic

Marwan ALshawi Mon, 12/22/2008 - 04:51

ok if u concerned about one input interface just apply ur policer policy on that physical interface


This Discussion