Summary How to rate limit a switch port on Catalyst IOS-XE using MQC policing and shaping, covering the difference between the two mechanisms, burst sizing, and the platform restrictions that most often cause a policy to fail.
There is no single "rate limit" command on IOS-XE. Rate limiting is done through the Modular QoS CLI (MQC), which follows the same three-step pattern regardless of what you are limiting:
class-map defines which traffic to act on.policy-map defines the action — policing or shaping.service-policy attaches the policy to an interface in a direction.The important decision is which of the two mechanisms to use, because they behave very differently under load even when configured to the same rate.
Both impose a maximum rate. The difference is what happens to traffic that exceeds it.
| Policing | Shaping | |
|---|---|---|
| Excess traffic | Dropped or marked down immediately | Buffered and sent later |
| Buffering | None | Yes, until buffers are exhausted |
| Adds latency | No | Yes, under load |
| Output rate | Bursty, sawtooth | Smooth |
| Effect on TCP | Causes retransmits and window collapse | Absorbs bursts, better throughput |
| Direction | Ingress or egress | Egress only |
| Command | police |
shape average |
Policing is the only option for ingress, because there is nowhere to buffer traffic that has not yet entered the switch. On egress you can use either, and shaping is usually the better choice for TCP-heavy traffic — a policer at 100 Mbps will typically deliver noticeably less than 100 Mbps of useful TCP throughput because the drops trigger congestion control.
Choose policing when you want a hard ceiling and drops are acceptable, or when limiting ingress. Choose shaping when the traffic is TCP and you care about achieved throughput.
Ingress is always policing. This example limits a port to 100 Mbps inbound.
policy-map RL-100M-IN
class class-default
police 100000000
conform-action transmit
exceed-action drop
!
interface GigabitEthernet1/0/10
description Rate limited access port
service-policy input RL-100M-IN
The rate is in bits per second. Valid values run from 8000 to 10000000000 (8 Kbps to 10 Gbps).
Using class-default applies the limit to all traffic on the port, which is what "rate limit the port" normally means. If you only want to limit a subset, define a class-map and match on it instead.
ip access-list extended BULK-TRAFFIC
permit tcp any any eq 445
!
class-map match-all BULK
match access-group name BULK-TRAFFIC
!
policy-map RL-BULK-IN
class BULK
police 20000000
conform-action transmit
exceed-action drop
class class-default
set dscp default
Egress supports both shaping and policing. Shaping is the more common choice for a port-level limit.
policy-map RL-100M-OUT
class class-default
shape average 100000000
!
interface GigabitEthernet1/0/10
service-policy output RL-100M-OUT
If a hard drop-based ceiling is genuinely wanted on egress, policing works in that direction too:
policy-map RL-100M-OUT-POLICE
class class-default
police 100000000
conform-action transmit
exceed-action drop
!
interface GigabitEthernet1/0/10
service-policy output RL-100M-OUT-POLICE
Both mechanisms accept a percentage of the interface bandwidth instead of an absolute rate. This is useful in templates applied across ports of differing speeds.
policy-map RL-10PC-IN
class class-default
police cir percent 10
conform-action transmit
exceed-action drop
!
policy-map RL-10PC-OUT
class class-default
shape average percent 10
Be careful applying a percentage-based policy to a port whose speed can change — the effective limit changes with it.
The committed burst (Bc) is how much traffic the policer will allow through in a momentary burst before enforcing the rate. It is optional; if omitted, IOS-XE computes a default.
The default is usually adequate. Where it is not, the common starting point is enough burst to cover 25–50 ms at the configured rate. Burst is configured in bytes, so for 100 Mbps at 30 ms:
100,000,000 bits/sec ÷ 8 = 12,500,000 bytes/sec
12,500,000 × 0.03 = 375,000 bytes
policy-map RL-100M-IN
class class-default
police cir 100000000 bc 375000
conform-action transmit
exceed-action drop
The explicit cir and bc keywords are clearer than relying on positional arguments and are less prone to being misread when someone else reviews the running configuration.
A burst that is too small causes drops on normal traffic bursts and depresses throughput well below the configured rate. This is the most common reason a policer "does not deliver the rate it was set to".
| Type | Parameters | Supported |
|---|---|---|
| Single-rate two-color | CIR, Bc | Yes |
| Dual-rate three-color | CIR, PIR (color-blind only) | Yes |
| Single-rate three-color | CIR, Bc, Be | No |
Dual-rate three-color allows a middle tier — traffic above CIR but below PIR can be treated differently from traffic above PIR.
policy-map RL-DUAL-RATE
class class-default
police cir 100000000 pir 200000000
conform-action transmit
exceed-action drop
violate-action drop
⚠️ Conform Action Must Be Transmit: On Catalyst wired targets the conform action must be
transmit— you cannot mark conforming traffic. Exceed and violate actions are limited to dropping or marking down, and markdown must use one of thecos2cos,prec2prec, ordscp2dscptable map types rather than a literal value, with the markdown type consistent across the policy. Confirm the exact markdown syntax against the configuration guide for your platform and release before deploying it.
show policy-map interface GigabitEthernet1/0/10
show policy-map interface GigabitEthernet1/0/10 input
show policy-map interface GigabitEthernet1/0/10 output
show policy-map RL-100M-IN
show run interface GigabitEthernet1/0/10
show policy-map interface is the command that matters. It reports conformed and exceeded byte and packet counts, which is how you confirm the policer is both installed and actually acting on traffic. A policy that shows zero counters in both columns is not seeing the traffic you think it is.
Watch for %QOS-6-POLICY_INST_FAILED in the logs — the policy is accepted into the configuration but silently fails to install in hardware, so the port runs unlimited.
QoS is not supported on the port-channel interface itself. The policy must be applied to each physical member port, and every member must carry the same policy — otherwise each link polices independently.
interface range GigabitEthernet1/0/1-2
service-policy input RL-100M-IN
Attaching a policy to a member produces a warning reminding you to apply it consistently across the bundle. Note that because each member polices separately, a two-member bundle with a 100 Mbps policy on each member permits up to 200 Mbps in aggregate, distributed by the hashing algorithm.
Only marking policies are supported on an SVI. You cannot police or shape a VLAN interface to rate limit a whole VLAN. Each physical port needs its own policer, and those policers cannot be aggregated across ports.
| Limit | Value |
|---|---|
| Policers per policy, per port | 63 |
| Classes per policy | 256 |
| Policy-maps per device | 1599 |
| Levels in a QoS hierarchy | 2 |
Policing cannot appear in both the parent and child of a hierarchy, and neither can marking. A port shaper must use class-default in the parent, and shaping is the only action the parent may contain. Port shapers and aggregate policers both require a hierarchical policy.
Shaping accounts for 20 bytes of inter-packet gap overhead per packet in hardware. With small packets this overhead is proportionally large, so the achieved rate can differ noticeably from the configured rate. Size shaping policies against expected packet sizes if precision matters.
Counters count packets, not bytes, and are only populated for policies containing a marking or policing action. A pure queuing or shaping policy will not produce class-map classification counters, which can look like the policy is not matching when it is working correctly.
Limiting an access port to 50 Mbps in both directions, policing inbound and shaping outbound.
policy-map RL-50M-IN
class class-default
police cir 50000000 bc 187500
conform-action transmit
exceed-action drop
!
policy-map RL-50M-OUT
class class-default
shape average 50000000
!
interface GigabitEthernet1/0/24
description Contractor port - 50M limit
switchport mode access
switchport access vlan 30
service-policy input RL-50M-IN
service-policy output RL-50M-OUT