In QoS design, how do traffic policing and traffic shaping differ, and where does each belong when a branch's 1 Gb/s port connects to a 100 Mb/s WAN contract?
answer
- same meter, different action
- drop or re-mark versus delay
- who owns the congestion point
- the provider polices at the contract
- nest queues inside the shaper
basics
~20 sPolicing drops or re-marks traffic above a rate at once, adding no delay; shaping buffers the excess and sends it later, adding delay instead of loss. The branch shapes egress to 100 Mb/s with queues inside; the provider polices.
solid answer
~50 sBoth compare traffic with a rate and burst allowance, usually via a token bucket. A **policer** drops or re-marks the excess at once: no buffer and no added delay, but loss that TCP senders read as congestion. RFC 2697 and RFC 2698 define its three-colour meters. A **shaper** buffers the excess and releases it at the target rate: smoother and loss-free until its buffer fills, but it adds delay and needs an egress queue. On a 1 Gb/s handoff to a 100 Mb/s contract the provider polices at 100 Mb/s, so the branch router must **shape its egress to the contract** and run its priority and weighted queues inside that shaper; otherwise its own queues never fill and the provider's policer drops voice and backups alike. Police at trust boundaries and domain edges; shape where a fast interface feeds a slower contracted rate.
code
pseudocode · 11 lines# srTCM, colour-blind mode (RFC 2697); sizes in bytes
# Tc starts at CBS, Te at EBS; CIR times per second:
# if Tc < CBS: Tc += 1 elif Te < EBS: Te += 1
function colour(packet_bytes):
if Tc - packet_bytes >= 0:
Tc -= packet_bytes
return GREEN # forward
if Te - packet_bytes >= 0:
Te -= packet_bytes
return YELLOW # e.g. re-mark AF11 -> AF12
return RED # drop; no bucket is decrementedgo deeper
Recall that policing drops or re-marks excess traffic immediately while shaping buffers it and sends it later at the allowed rate.
Explain the token-bucket meters behind both, the srTCM and trTCM colours, and why a shaper adds delay but avoids loss until its buffer fills.
Show that you move the congestion point into your own router by shaping to the contract, nest queuing inside it, and police at trust boundaries.
Weigh the provider's enforcement model, contract headroom, burst sizes and where you need control, against the delay a shaper adds to interactive traffic.
## Two ways to enforce a rate Policing and shaping both measure traffic against a **profile**, a rate plus a burst allowance usually tracked with a token bucket, and differ in what they do with traffic that exceeds it. RFC 2475 defines them: - **Policing**: discarding packets within a traffic stream according to the state of a meter enforcing a profile. Many policers can instead **re-mark** excess traffic, which RFC 2475 calls re-marking by a marker. - **Shaping**: delaying packets within a stream so that it conforms to a profile. A shaper has a finite buffer; when the buffer is full, packets are discarded. RFC 2475 notes that a dropper can be implemented as a shaper whose buffer is set to zero, or a few, packets. | | Policer | Shaper | |---|---|---| | Excess traffic | dropped or re-marked at once | buffered and sent later | | Delay added | none | up to the buffer depth | | Buffer needed | no | yes | | Where it runs | ingress or egress | normally egress, where a queue exists | | What TCP senders see | losses, read as congestion | queuing delay first, loss only when the buffer fills | | Typical use | enforcing a contract at a domain edge | conforming to a contract on the sending side | ## The meters behind policers RFC 2697 and RFC 2698, both Informational, define three-colour markers: - **Single Rate Three Color Marker (srTCM)**: a Committed Information Rate (CIR), a Committed Burst Size (CBS) and an Excess Burst Size (EBS). A packet is green if it does not exceed the CBS, yellow if it exceeds the CBS but not the EBS, and red otherwise. - **Two Rate Three Color Marker (trTCM)**: a Peak Information Rate (PIR) with a Peak Burst Size (PBS), and a CIR with a CBS. Red above the PIR, yellow above the CIR, green otherwise. The colours feed actions: green forwarded, yellow re-marked to a higher drop precedence (AF11 to AF12, for instance), red dropped. RFC 2697 measures the CIR in bytes of IP packets per second, IP header included and link-layer headers excluded. RFC 4594 recommends single-rate policing with burst control for EF, and two-rate or single-rate three-colour marking for the AF classes. ## The branch scenario A branch router connects to its provider with a 1 Gb/s Ethernet port, but the contract is 100 Mb/s, and the provider polices its ingress at 100 Mb/s. Without shaping: 1. The router sees a 1 Gb/s interface, so its own output queue rarely builds and its priority and weighted queues never engage. 2. Bursts leave at 1 Gb/s and reach the provider's policer, which does not know your classes. Whatever arrives once its tokens run out is dropped, voice included. 3. Calls break up although the router's queuing policy looks correct. With a shaper at 100 Mb/s on the router's egress, and the queuing policy nested inside it (a parent shaper with a child policy of priority and weighted queues): 1. The congestion point moves into your router, where your policy decides. 2. Voice rides the priority queue inside the shaped rate; backups wait in their own queue. 3. The provider's policer sees conforming traffic and drops nothing. Shape slightly below the contract when the provider counts layer-2 overhead differently from your shaper; implementations differ in which bytes a shaper counts. Shapers also release traffic in per-interval bursts whose length is an implementation setting; a long interval adds delay variation, which is another reason voice must sit in the priority queue inside the shaper. ## The arithmetic of a burst Take a policer with a CIR of 100 Mb/s and a CBS of 125,000 bytes (1 Mbit, which is 10 ms of traffic at the CIR) and no excess bucket, facing a burst arriving at 1 Gb/s: 1. Tokens arrive at 100 Mb/s and are consumed at 1 Gb/s, a net loss of 900 Mb/s. 2. The full bucket empties in 1 Mbit divided by 900 Mb/s, about 1.1 ms. 3. From then on only the token arrival rate conforms: 100 of every 1,000 Mb/s offered, so about 90 % of the rest of the burst is red. A shaper with enough buffer would deliver the same burst at 100 Mb/s with no loss, at the cost of queuing delay. ## Where each belongs - **Police** at the ingress of a trust boundary or domain edge: EF from access ports (RFC 4594), customer traffic at a provider's edge, the priority queue itself (RFC 3246). - **Shape** at egress where a faster interface feeds a slower contracted or downstream rate: a branch handoff, or a hub sending to slower spokes. - **Never protect voice with a shaper alone**: a shaper adds delay, so voice needs the priority queue inside the shaper.
- Why does a policed TCP transfer often get well below the policed rate?A policer drops whole bursts once its bucket empties, and the TCP sender treats each loss as congestion and cuts its sending rate, then climbs back slowly. With a small burst size the flow keeps hitting the limit and backing off, so its average sits below the rate. A larger committed burst, or shaping on the sending side, lets the flow run close to the contract.
- Why is a policer, not a shaper, used to limit the voice priority queue?Shaping excess voice would delay it, and late voice is useless to a receiver whose de-jitter buffer has already played past that moment. RFC 3246 requires excess EF to be discarded, which keeps the priority queue short and the delay of conforming voice low. The real cure for excess voice is admission control, so the policer rarely fires.
saying these in an interview costs you the question
- Policing and shaping are the same thing at different places.
- A shaper drops excess packets immediately, just like a policer.
- A policer adds delay because it holds packets until tokens arrive.
- The router's queuing policy works on a 1 Gb/s port even if the contract is 100 Mb/s.
- Shaping is the right tool to cap the voice priority queue.