定义access group
access-list 130 permit ip any 10.30.168.0 0.0.0.255
access-list 150 permit ip any 10.50.168.0 0.0.0.255
access-list 150 permit ip any 10.50.168.0 0.0.0.255
定义class
class-map match-all BYOD
match access-group 150
class-map match-all GUEST
match access-group 130
match access-group 150
class-map match-all GUEST
match access-group 130
定义policy
policy-map nonwork
class BYOD
police 4000000 1000000 exceed-action drop
trust dscp
class GUEST
police 4000000 500000 exceed-action drop
trust dscp
class BYOD
police 4000000 1000000 exceed-action drop
trust dscp
class GUEST
police 4000000 500000 exceed-action drop
trust dscp
应用policy
#conf t
(config)#interface FastEthernet1/0/1
(config-if)#service-policy input nonwork
(config)#interface FastEthernet1/0/1
(config-if)#service-policy input nonwork