QoS之拥塞管理两种配置方法

需求分析

1、voip语音业务为ef快速转发

2、video视频业务为确保转发af31

3、data业务为确保转发af11

4、两边路由入口都进行流量分类与标记(一般入口用复杂流分类mqc做,ds域中间使用简单流分类)

5、QoS拥塞管理配置(两种一种是r1用基于队列的,一种是r2基于mqc的,实现中选择一种就行了)

6、r1上的拥塞管理用基于队伍的拥塞管理ef队列用pq调度,af31和af11用wfq调度(wfq可以配置权重值)

7、r2上的拥塞管理用基于mqc的拥塞管理,voip用llq队列配置最大带宽20M,video确保带宽50M,data确保30M

为什么voip用llq,因为llq用的是流量监管限速,ef用的是流量整形限速,所以llq比ef延迟更低,llq也叫低延迟队列

R1

acl number 3000

rule 5 permit ip source 192.168.1.0 0.0.0.255

acl number 3001

rule 5 permit ip source 192.168.2.0 0.0.0.255

acl number 3002

rule 5 permit ip source 192.168.3.0 0.0.0.255

qos queue-profile p1

queue 1 weight 30

queue 3 weight 50

schedule wfq 1 to 3 pq 5

traffic classifier video operator or

if-match acl 3001

traffic classifier voip operator or

if-match acl 3000

traffic classifier data operator or

if-match acl 3002

traffic behavior ef

remark dscp ef

traffic behavior af11

remark dscp af11

traffic behavior af31

remark dscp af31

traffic policy p1

classifier video behavior af31

classifier voip behavior ef

classifier data behavior af11

interface GigabitEthernet0/0/0

ip address 10.0.12.1 255.255.255.0

trust dscp override

qos queue-profile p1

interface GigabitEthernet0/0/1

ip address 10.0.11.1 255.255.255.0

traffic-policy p1 inbound

ospf 1

default-route-advertise

area 0.0.0.0

network 10.0.11.1 0.0.0.0

ip route-static 0.0.0.0 0.0.0.0 10.0.12.2

r2

acl number 3000

rule 5 permit ip source 172.16.1.0 0.0.0.255

acl number 3001

rule 5 permit ip source 172.16.2.0 0.0.0.255

acl number 3002

rule 5 permit ip source 172.16.3.0 0.0.0.255

traffic classifier video operator or

if-match acl 3001

traffic classifier ef operator or

if-match dscp ef

traffic classifier af_data operator or

if-match dscp af11

traffic classifier voip operator or

if-match acl 3000

traffic classifier af_video operator or

if-match dscp af31

traffic classifier data operator or

if-match acl 3002

traffic behavior llq

queue llq bandwidth 20480 cbs 512000

traffic behavior ef

remark dscp ef

traffic behavior af_data

queue af bandwidth 30720

traffic behavior af_video

queue af bandwidth 51200

traffic behavior af11

remark dscp af11

traffic behavior af31

remark dscp af31

traffic policy p2

classifier ef behavior llq

classifier af_video behavior af_video

classifier af_data behavior af_data

traffic policy p1

classifier video behavior af31

classifier voip behavior ef

classifier data behavior af11

interface GigabitEthernet0/0/0

ip address 10.0.12.2 255.255.255.0

trust dscp override

traffic-policy p2 outbound

interface GigabitEthernet0/0/1

ip address 10.0.22.1 255.255.255.0

traffic-policy p1 inbound

ospf 1

default-route-advertise

area 0.0.0.0

network 10.0.22.1 0.0.0.0

ip route-static 0.0.0.0 0.0.0.0 10.0.12.1

sw1

vlan batch 10 to 11 20 30

dhcp enable

interface Vlanif10

ip address 192.168.1.1 255.255.255.0

dhcp select interface

interface Vlanif11

ip address 10.0.11.2 255.255.255.0

interface Vlanif20

ip address 192.168.2.1 255.255.255.0

dhcp select interface

interface Vlanif30

ip address 192.168.3.1 255.255.255.0

dhcp select interface

interface MEth0/0/1

interface GigabitEthernet0/0/1

port link-type access

port default vlan 11

interface GigabitEthernet0/0/2

port link-type access

port default vlan 10

interface GigabitEthernet0/0/3

port link-type access

port default vlan 20

interface GigabitEthernet0/0/4

port link-type access

port default vlan 30

ospf 1

import-route direct

area 0.0.0.0

network 10.0.11.2 0.0.0.0

sw2

vlan batch 10 20 22 30

dhcp enable

interface Vlanif10

ip address 172.16.1.1 255.255.255.0

dhcp select interface

interface Vlanif20

ip address 172.16.2.1 255.255.255.0

dhcp select interface

interface Vlanif22

ip address 10.0.22.2 255.255.255.0

interface Vlanif30

ip address 172.16.3.1 255.255.255.0

dhcp select interface

interface MEth0/0/1

interface GigabitEthernet0/0/1

port link-type access

port default vlan 22

interface GigabitEthernet0/0/2

port link-type access

port default vlan 10

interface GigabitEthernet0/0/3

port link-type access

port default vlan 20

interface GigabitEthernet0/0/4

port link-type access

port default vlan 30

ospf 1

import-route direct

area 0.0.0.0

network 10.0.22.2 0.0.0.0

mqc配置查看

DS域内只配这个一条命令简单流分类即可,可以不带override,带的话就是能对标记好的流量的优先级进行外部和内部优先级修映射改后再发给另一个ds设备(意思就是可以改dscp-dscp的两列的对应关系映射)

r1-GigabitEthernet0/0/0\]trust dscp override \[r2-GigabitEthernet0/0/0\]trust dscp override dscp-dscp内外优先级映射查看0-63 ![在这里插入图片描述](https://i-blog.csdnimg.cn/direct/d58092dc73b144f399bd97709caa0f77.png) ![在这里插入图片描述](https://i-blog.csdnimg.cn/direct/18de236e975645419a458ec1f6a89631.png) r1出口捉包结果捉包查看 ![在这里插入图片描述](https://i-blog.csdnimg.cn/direct/d3a2090922dd420190243f164a3faeaf.png) 两边三种业务ping后测试发现队列1是video 、3是 data,分别对af31、af11,队列5是voip对应ef,由此R1可以根据此队列进行拥塞管理配置 ![在这里插入图片描述](https://i-blog.csdnimg.cn/direct/62d973eee7474a7799bf75a4c7bbd068.png) r1上用基于队列方式配,然后进行拥塞管理权重调整,wfq会根据权重值大的分配带宽高低(默认是10) r1上配 qos queue-profile p1 queue 1 weight 30 queue 3 weight 50 schedule wfq 1 to 3 pq 5 int g 0/0/0 qos queue-profile p1 查看权重值调整结果 ![在这里插入图片描述](https://i-blog.csdnimg.cn/direct/8a6162d0d8e440e9a933627e23adf136.png) r2上用基于mqc的方式配 traffic classifier ef operator or if-match dscp ef traffic classifier af_data operator or if-match dscp af11 traffic classifier af_video operator or if-match dscp af31 traffic behavior llq queue llq bandwidth 20480 cbs 512000 traffic behavior af_data queue af bandwidth 30720 traffic behavior af_video queue af bandwidth 51200 traffic policy p2 classifier ef behavior llq classifier af_video behavior af_video classifier af_data behavior af_data interface GigabitEthernet0/0/0 ip address 10.0.12.2 255.255.255.0 trust dscp override traffic-policy p2 outbound 流策略查看 ![在这里插入图片描述](https://i-blog.csdnimg.cn/direct/848104aaaee44cfbbc816bba1a4b7e7c.png)

相关推荐
旺仔.2911 小时前
Linux 信号详解
linux·运维·网络
源远流长jerry4 小时前
在 Ubuntu 22.04 上配置 Soft-RoCE 并运行 RDMA 测试程序
linux·服务器·网络·tcp/ip·ubuntu·架构·ip
虾..4 小时前
UDP协议
网络·网络协议·udp
w-w0w-w5 小时前
Unix网络编程
服务器·网络·unix
未知鱼5 小时前
Python安全开发之子域名扫描器(含详细注释)
网络·python·安全·web安全·网络安全
寂柒5 小时前
序列化与反序列化
linux·网络
志栋智能6 小时前
超自动化巡检:应对复杂IT环境的必然选择
运维·网络·安全·web安全·自动化
上海云盾-小余7 小时前
云主机安全加固:从系统、网络到应用的零信任配置
网络·安全·php
QCzblack8 小时前
见面考复现
网络
Eric.Lee20219 小时前
查看ubuntu机器正在使用的网络端口
网络·ubuntu·php