Configure rate limit at packet level
To configure rate limiting at packet level, perform the following tasks
-
Enable load balancing
-
Add stream selector
-
Add stream identifier
-
Add responder policy
-
Add load balancing virtual server
-
Bind responder policy
To enable load balancing feature
enable ns feature lb
To add a stream selector
add stream selector packetlimitselector client.ip.src client.tcp.srcport client.ip.dst client.tcp.dstport
To add a stream identifier
add stream identifier packetlimitidentifier packetlimitselector -interval 1
To enable tracking of ACK only packets
set stream identifier packetlimitidentifier –trackAckOnlyPackets ENABLED
To add a responder policy
add responder policy packet_rate_sessionpolicy "ANALYTICS.STREAM(\"packetlimitidentifier\").COLLECT_STATS(\"PACKET_LIMIT\", <max_threshold_PPS>, ACTION, 0/1)" NOOP
-
\<max\_threshold\_PPS\> is the maximum number of packets allowed through the connection per second.
-
ACTION can be DROP or RESET.
-
0 or 1 represents the limit type; 0 represents the BURSTY limit type and 1 represents the SMOOTH limit type.
add responder policy packet_rate_sessionpolicy "ANALYTICS.STREAM(\"packetlimitidentifier\").COLLECT_STATS(\"PACKET_LIMIT\", 40, RESET, 0)" NOOP
To add a load balancing virtual server
add lb vserver <name> <serviceType> <ip> <port>
add lb vserver Vserver-lb-1 HTTP 10.102.20.200 80
To bind a responder policy
bind responder global <policyName> <priority> [<gotoPriorityExpression>] [-type <type>] [-invoke (<labelType> <labelName>) ]
bind lb vserver <name>@ (-policyName <string>@ [-priority <positive_integer>]
bind responder global packet_rate_sessionpolicy 101 END -type REQ_DEFAULT
bind responder global packet_rate_sessionpolicy 102 END -type
bind lb vserver v1 -policyname packet_rate_sessionpolicy -priority 10