Example: Wholesale L2TP Model Hierarchical Policy Configuration

In this example:

To use this example, you must configure the following:

  1. Create a rate-limit that can be shared across all forwarding interfaces. Create an external parent group to hold this rate limit.
    host1(config)#rate-limit-profile VLAN_RATE two-rate hierarchical host1(config-rate-limit-profile)#committed-rate 12000000 host1(config-rate-limit-profile)#committed-action transmit final host1(config-rate-limit-profile)#exit
    host1(config)#parent-group EPG1 host1(config-parent-group)#rate-limit-profile VLAN_RATE host1(config-parent-group)#exit
  2. Create a policy list to attach to users 1 and 2.
    host1(config)#rate-limit-profile IP_RATE two-rate hierarchical host1(config-rate-limit-profile)#committed-rate 1000000 host1(config-rate-limit-profile)#committed-action transmit unconditional host1(config-rate-limit-profile)#peak-rate 11000000 host1(config-rate-limit-profile)#conformed-action transmit conditional host1(config-rate-limit-profile)#exit
    host1(config)#policy-parameter A hierarchical host1(config-policy-parameter)#exit host1(config)#ip policy-list IP_POL host1(config-policy-list)#classifier-group * external parent-group EPG1
    parameter A
    host1(config-policy-list-classifier-group)#rate-limit-profile IP_RATE host1(config-policy-list-classifier-group)#exit host1(config-policy-list)#exit
  3. Create a policy list to attach to user 3.
    host1(config)#rate-limit-profile L2TP_RATE two-rate hierarchical host1(config-rate-limit-profile)#committed-rate 10000000 host1(config-rate-limit-profile)#committed-action transmit unconditional host1(config-rate-limit-profile)#exit
    host1(config)#l2tp policy-list L2TP_POL host1(config-policy-list)#classifier-group * external parent-group EPG1
    parameter A
    host1(config-policy-list-classifier-group)#rate-limit-profile L2TP_RATE host1(config-policy-list-classifier-group)#exit host1(config-policy-list)#exit
  4. In both terminated users' record in RADIUS, you must specify the ingress policy name IP_POL. You must specify the ingress policy name L2TP_POL in the tunneled user's record in RADIUS. However, be sure to specify the policy parameter through a profile.
    host1(config)#profile PPPOE_PROF1 host1(config-profile)#ip policy-parameter hierarchical A 1 host1(config-profile)#l2tp policy-parameter hierarchical A 1 host1(config-profile)#exit
    host1(config)#interface fastEthernet 3/0.1 host1(config-interface)#vlan id 1 host1(config-interface)#encapsulation pppoe host1(config-interface)#profile PPPOE_PROF1 host1(config-interface)#pppoe auto-configure host1(config-interface)#exit

Related Documentation