<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic QoS Service-Policies on Dynamic VTI (IPSEC) Interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/qos-service-policies-on-dynamic-vti-ipsec-interfaces/m-p/519465#M1055106</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking at setting up a large scale (1000+) client VPN system and I'm trying to understand the new QoS capabilities of dynamic VTIs. From what I have read, I believe I can setup both inbound and output service policies for each VPN user. What I'd like to know is how these service policies affect the physical interface service policies?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My initial thoughts are that VTI service policies can only rate-limit/police matching traffic or remark traffic for use on the physical outbound service policy. This also implies that the re-marked DSCP/ToS is automatically copied to the IPSEC header and the IPSEC head DSCP/ToS setting used on the outbound service policy. Is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally I'd like to setup an outbound LLQ for VoIP traffic. Is it possible / worthwhile setting up an LLQ on the VTI service policy? - or is it better to policy each user's VoIP traffic to a limit and rely on the outbound physical service policy to run the LLQ for all VoIP traffic combined?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or comments would be greatly appreciated,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:54:56 GMT</pubDate>
    <dc:creator>richardwatson</dc:creator>
    <dc:date>2020-02-21T08:54:56Z</dc:date>
    <item>
      <title>QoS Service-Policies on Dynamic VTI (IPSEC) Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/qos-service-policies-on-dynamic-vti-ipsec-interfaces/m-p/519465#M1055106</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking at setting up a large scale (1000+) client VPN system and I'm trying to understand the new QoS capabilities of dynamic VTIs. From what I have read, I believe I can setup both inbound and output service policies for each VPN user. What I'd like to know is how these service policies affect the physical interface service policies?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My initial thoughts are that VTI service policies can only rate-limit/police matching traffic or remark traffic for use on the physical outbound service policy. This also implies that the re-marked DSCP/ToS is automatically copied to the IPSEC header and the IPSEC head DSCP/ToS setting used on the outbound service policy. Is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally I'd like to setup an outbound LLQ for VoIP traffic. Is it possible / worthwhile setting up an LLQ on the VTI service policy? - or is it better to policy each user's VoIP traffic to a limit and rely on the outbound physical service policy to run the LLQ for all VoIP traffic combined?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or comments would be greatly appreciated,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-service-policies-on-dynamic-vti-ipsec-interfaces/m-p/519465#M1055106</guid>
      <dc:creator>richardwatson</dc:creator>
      <dc:date>2020-02-21T08:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: QoS Service-Policies on Dynamic VTI (IPSEC) Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/qos-service-policies-on-dynamic-vti-ipsec-interfaces/m-p/519466#M1055107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,  re-marked DSCP/ToS is automatically copied to the IPSEC header and the IPSEC head DSCP/ToS setting used on the outbound service policy. Also, it is better to policy each user's VoIP traffic to a limit and rely on the outbound physical service policy to run the LLQ for all VoIP traffic combined&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2006 12:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-service-policies-on-dynamic-vti-ipsec-interfaces/m-p/519466#M1055107</guid>
      <dc:creator>ebreniz</dc:creator>
      <dc:date>2006-05-26T12:47:39Z</dc:date>
    </item>
  </channel>
</rss>

