<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SecureStack Rate Limiting not Functioning as Expected for Untagged Traffic in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/securestack-rate-limiting-not-functioning-as-expected-for/m-p/46858#M422</link>
    <description>Article ID: 7177 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
Matrix C2&lt;BR /&gt;
SecureStack C2&lt;BR /&gt;
Firmware 3.03.38 and lower&lt;BR /&gt;
SecureStack B2&lt;BR /&gt;
Firmware 3.00.18 and lower&lt;BR /&gt;
NetSight Policy Manager&lt;BR /&gt;
Version 2.0.1 and lower &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
Rate limiting&lt;BR /&gt;
802.1Q&lt;BR /&gt;
Policy&lt;BR /&gt;
UPN &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
Rate limiting not functioning for untagged traffic&lt;BR /&gt;
'set port ratelimit' &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
802.1Q-VLAN-tagged traffic can be rate limited according to its priority association based on policy. &lt;BR /&gt;
&lt;BR /&gt;
Untagged traffic, on the other hand, can&lt;I&gt;not&lt;/I&gt; be rate limited according to its priority association based on policy or ingress port priority. This is because priority based (port) rate limiters are applied by hardware prior to packet classification. The impact of this is that all non-priority tagged traffic will have the limiter associated with the default queue (queue 0) applied. This is true even if the packet is later classified to a new priority level. If, however, a rate limit is created for priority 0, all priority (0-7) untagged traffic will be rate limited. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Upgrade to Policy Manager 2.1 or higher, and use Role Based Rate Limiting. &lt;BR /&gt;
&lt;BR /&gt;
Role Based Rate Limiting provides a very granular rate limiting solution. Unlike our traditional Priority Based Rate Limiting, role based enables rate limits to be assigned at the role and rule level rather than assigning rate limits to 802.1p priority queues. &lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://extranet.enterasys.com/downloads/Pages/NMS.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;Release notes&lt;/A&gt; state:&lt;BR /&gt;
Policy Manager now supports inbound role-based rate limiting on SecureStack C2/B2 Devices.&lt;BR /&gt;
&lt;BR /&gt;
This also requires the use of C2 firmware 4.00.24 or higher, and/or B2 firmware 3.01.16 or higher.</description>
    <pubDate>Wed, 27 Nov 2013 02:10:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-11-27T02:10:00Z</dc:date>
    <item>
      <title>SecureStack Rate Limiting not Functioning as Expected for Untagged Traffic</title>
      <link>https://community.extremenetworks.com/t5/faqs/securestack-rate-limiting-not-functioning-as-expected-for/m-p/46858#M422</link>
      <description>Article ID: 7177 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
Matrix C2&lt;BR /&gt;
SecureStack C2&lt;BR /&gt;
Firmware 3.03.38 and lower&lt;BR /&gt;
SecureStack B2&lt;BR /&gt;
Firmware 3.00.18 and lower&lt;BR /&gt;
NetSight Policy Manager&lt;BR /&gt;
Version 2.0.1 and lower &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
Rate limiting&lt;BR /&gt;
802.1Q&lt;BR /&gt;
Policy&lt;BR /&gt;
UPN &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
Rate limiting not functioning for untagged traffic&lt;BR /&gt;
'set port ratelimit' &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
802.1Q-VLAN-tagged traffic can be rate limited according to its priority association based on policy. &lt;BR /&gt;
&lt;BR /&gt;
Untagged traffic, on the other hand, can&lt;I&gt;not&lt;/I&gt; be rate limited according to its priority association based on policy or ingress port priority. This is because priority based (port) rate limiters are applied by hardware prior to packet classification. The impact of this is that all non-priority tagged traffic will have the limiter associated with the default queue (queue 0) applied. This is true even if the packet is later classified to a new priority level. If, however, a rate limit is created for priority 0, all priority (0-7) untagged traffic will be rate limited. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Upgrade to Policy Manager 2.1 or higher, and use Role Based Rate Limiting. &lt;BR /&gt;
&lt;BR /&gt;
Role Based Rate Limiting provides a very granular rate limiting solution. Unlike our traditional Priority Based Rate Limiting, role based enables rate limits to be assigned at the role and rule level rather than assigning rate limits to 802.1p priority queues. &lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://extranet.enterasys.com/downloads/Pages/NMS.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;Release notes&lt;/A&gt; state:&lt;BR /&gt;
Policy Manager now supports inbound role-based rate limiting on SecureStack C2/B2 Devices.&lt;BR /&gt;
&lt;BR /&gt;
This also requires the use of C2 firmware 4.00.24 or higher, and/or B2 firmware 3.01.16 or higher.</description>
      <pubDate>Wed, 27 Nov 2013 02:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/securestack-rate-limiting-not-functioning-as-expected-for/m-p/46858#M422</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-11-27T02:10:00Z</dc:date>
    </item>
  </channel>
</rss>

