Cisco Support Community
Community Member

traffic policing with cbwfq


i have a question regarding policing.

we have frame-relay-customers connected - these fr-pakets are forwardet over a ip-tunnel.

to limit the fr-traffic in our ip-cloud, i configured the policy.

class-map match-all tu414813222

match input-interface Tunnel414813222


policy-map policy_fr-kunden_414813

class tu414813222

police cir 64000 bc 12032 pir 64000

conform-action set-prec-transmit 3

exceed-action drop

violate-action drop



interface Tunnel414813

description R-Steyrst1: PE/Transport-Tunnel zu MPLSRBGOCE01 (Tu414813)

bandwidth 64

ip unnumbered Loopback414813222

service-policy output policy_fr-kunden_414813

keepalive 10 3

tunnel source Loopback0

tunnel destination


interface Tunnel414813222

description R-Steyrst1: DLCI-222 f. Kunde RRW-Steyr (Tu414813222)

bandwidth 64

no ip address

keepalive 10 3

tunnel source Loopback414813222

tunnel destination



interface Serial0/3

description Int S0/3 Verbdg. zum RRW-Router (FR-Switching)

no ip address

encapsulation frame-relay IETF

clockrate 64000

no fair-queue

frame-relay lmi-type q933a

frame-relay intf-type dce

frame-relay route 16 interface Tunnel414813222 222


r-steyrst1#sh pol

r-steyrst1#sh policy-map interface Tunnel414813


Service-policy output: policy_fr-kunden_414813

Class-map: tu414813222 (match-all)

946 packets, 93974 bytes

5 minute offered rate 0 bps, drop rate 0 bps

Match: input-interface Tunnel414813222


cir 64000 bps, bc 12032 bytes

pir 64000 bps, be 12032 bytes

conformed 835 packets, 88646 bytes; actions:

set-prec-transmit 3

exceeded 0 packets, 0 bytes; actions:


violated 0 packets, 0 bytes; actions:


conformed 0 bps, exceed 0 bps, violate 0 bps

Class-map: class-default (match-any)

0 packets, 0 bytes

5 minute offered rate 0 bps, drop rate 0 bps

Match: any



The question is:

i can see that 946 packets are matched by the class-map - but only 835 packets are conformed.

where are the regarding 111 packets ??


Re: traffic policing with cbwfq

I am not sure if I understand the configuration correctly. It is not clear as to how the traffic flows in the tunnels. The service policy is applied to a particular tunnel interface, but the frame relay connection seems to switched out of another interface which is matched in the policy map. Just wondering how this is matched by the class-map.

CreatePlease to create content