This command configures a security queue policy for traffic being extracted from the datapath to the CSM for firewall processing. When a security queue policy is created, two queues are created automatically for the extracted traffic: queue 1 for best-effort traffic and queue 2 for expedited traffic. The queue number and type for these two queues is not configurable.
The no form of this command removes the security queue policy.
n/a
This command configures a description for the security queue policy being referenced.
The no form of this command removes the description.
n/a
This command enables the context to configure parameters related to the queue type for the traffic extracted from the datapath to the CSM. When the security queue policy is created, a set of queues is automatically created: queue 1 for best-effort traffic and queue 2 for expedited traffic. When the best-effort and expedited queues are created, default values are assigned to their information rate parameters.
The no form of this command removes the queue-id from the security queue policy.
n/a
This command overrides the default Committed Buffer Space (CBS) reserved for the specified queue. The value is configured in kilobytes.
The no form of this command returns the CBS to the default value for the queue type.
This command configures the percentage of the queue used exclusively by high-priority packets. The specified value overrides the default value for the queue type.
The no form of this command restores the default high-priority reserved size for the queue type.
This command sets the Maximum Burst Size (MBS) value for buffers of a specified queue. The value is configured either in bytes or in kilobytes and overrides the default MBS value.
The no form of this command returns the MBS to the default value for the queue type.
This command sets the Peak Information Rate (PIR) value and optional Committed Information Rate (CIR) for a specified queue. The values are configured in kilobytes and override the default PIR and CIR values.
The no form of this command returns the PIR and CIR to their default values for the queue type, assigned when the security queue policy for firewall traffic was created.
This command copies existing policy entries for a security queue QoS policy to another security queue policy. This command is a configuration-level maintenance tool used to create new policies using existing policies. It also allows bulk modifications to an existing policy with the use of the overwrite keyword.
n/a
![]() | Note: The following command outputs are examples only; actual displays may differ depending on supported functionality and user configuration. |
This command displays security queue information.
The following output is an example of security policy information, and Table 69 describes the fields.
Label | Description |
QoS Security Queue Policy | |
Policy-id | The ID that uniquely identifies the security queue policy |
Description | A text string that helps identify the security queue policy’s context in the configuration file |
Q | The security queue identifier, either 1 or 2 |
CIR | The committed information rate for the security queue |
PIR | The peak information rate for the security queue |
CBS | The committed buffer space for the security queue |
MBS | The maximum burst size for the security queue |
HiPrio | The percentage of the queue used exclusively by high-priority packets |
Associations | |
MDA | The adapter card slot number indicating the direction of traffic to which the security queue applies |