<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Traffic Policing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630553#M1090865</link>
    <description>&lt;P&gt;Then try the command show service-policy&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jun 2022 06:55:39 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2022-06-13T06:55:39Z</dc:date>
    <item>
      <title>Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630283#M1090849</link>
      <description>&lt;P&gt;Hi Community, I hope you can help me with this config.&lt;/P&gt;&lt;P&gt;I have an inside SFTP server 192.168.2.82 running on tcp port 20000&lt;/P&gt;&lt;P&gt;I would like to limmit the bandwith, so it not taking up all up and download.&lt;/P&gt;&lt;P&gt;Initially I have a:&lt;/P&gt;&lt;PRE&gt;access-list SFTP extended permit tcp any host 192.168.2.82 eq 20000

class-map SFTP-shaping
match access-list SFTP

policy-map outside-policy
class SFTP-shaping
police input 1500000 5000 conform-action exceed-action drop
police output 1500000 5000 conform-action exceed-action drop
service-policy outside-policy interface outside&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;However it dosn't seem to work, regardles of what numbers I config, it still is at full speed of the link.&lt;/P&gt;&lt;P&gt;Any bright ideas?&lt;/P&gt;&lt;P&gt;Config is attached&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards Soter&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2022 10:59:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630283#M1090849</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2022-06-12T10:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630377#M1090850</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1298050"&gt;@Kasper Elsborg&lt;/a&gt; I notice you've got &lt;STRONG&gt;prompt hostname context&lt;/STRONG&gt; configured, are you running in multi-context mode? If that's the case, QoS is not supported in multi-context mode. &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/ha-contexts.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/ha-contexts.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2022 17:23:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630377#M1090850</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-06-12T17:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630389#M1090852</link>
      <description>&lt;P&gt;Have you verified that you are actually hitting the policy map?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show policy-map outside-policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first thing I noticed, though I do not believe it is the issue, is that you are missing the "conform-action transmit" command.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2022 19:15:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630389#M1090852</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-12T19:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630536#M1090862</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I wasn't supposed to run in context mode.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a look here&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/mngcntxt.html#wp1036360" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/mngcntxt.html#wp1036360&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but non of the cmd to remove context mode is working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br. Soter&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 06:24:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630536#M1090862</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2022-06-13T06:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630541#M1090864</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;I am not sure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have this command?&lt;/P&gt;&lt;PRE&gt;asa5516(config)# sh policy-?

exec mode commands/options:
  policy-list    policy-route  
asa5516(config)# sh policy-&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;but I do have:&lt;/P&gt;&lt;PRE&gt;asa5516# sh service-policy 

Global policy: 
  Service-policy: global_policy
    Class-map: inspection_default
      Inspect: h323 h225 _default_h323_map, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
               tcp-proxy: bytes in buffer 0, bytes dropped 0
      Inspect: h323 ras _default_h323_map, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: ip-options _default_ip_options_map, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: netbios, packet 1538, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: rsh, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: rtsp, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
               tcp-proxy: bytes in buffer 0, bytes dropped 0
      Inspect: skinny , packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
               tcp-proxy: bytes in buffer 0, bytes dropped 0
      Inspect: esmtp _default_esmtp_map, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: sqlnet, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: sunrpc, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
               tcp-proxy: bytes in buffer 0, bytes dropped 0
      Inspect: tftp, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: sip , packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
               tcp-proxy: bytes in buffer 0, bytes dropped 0
      Inspect: xdmcp, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: icmp, packet 79072, lock fail 0, drop 1297, reset-drop 0, 5-min-pkt-rate 1 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: dns preset_dns_map dynamic-filter-snoop, packet 64300, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 1 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: ftp strict, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: http, packet 310743, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 1 pkts/sec, v6-fail-close 0 sctp-drop-override 0
      Inspect: icmp error, packet 1, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0
    Class-map: global-class
      Inspect: http Http_Map1, packet 0, lock fail 0, drop 0, reset-drop 0, 5-min-pkt-rate 0 pkts/sec, v6-fail-close 0 sctp-drop-override 0

Interface outside:
  Service-policy: outside-policy
    Class-map: outside-class1
      Set connection policy: per-client-embryonic-max 50 
        drop 0
      Set connection timeout policy:
        embryonic 0:00:05 
        DCD: disabled, retry-interval 0:00:15, max-retries 5
        DCD: client-probe 0, server-probe 0, conn-expiration 0
    Class-map: SFTP-shaping
      Input police Interface outside:
        cir 3000000 bps, bc 5000 bytes
        conformed 111052 packets, 9330396 bytes; actions:  transmit
        exceeded 2122 packets, 401076 bytes; actions:  drop
        conformed 968 bps, exceed 40 bps
      Output police Interface outside:
        cir 3000000 bps, bc 5000 bytes
        conformed 0 packets, 0 bytes; actions:  transmit
        exceeded 0 packets, 0 bytes; actions:  drop
        conformed 0 bps, exceed 0 bps
asa5516# &lt;/PRE&gt;&lt;P&gt;and it looks like the output police is not working, or am I looking at this the wrong way? Output is when I'm downloading to the internet?&lt;/P&gt;&lt;P&gt;however it is hitting the access-list&lt;/P&gt;&lt;PRE&gt;asa5516(config)# sh access-list 
access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)
            alert-interval 300
access-list SFTP; 1 elements; name hash: 0xc8056573
access-list &lt;STRONG&gt;SFTP line 1 extended permit tcp any host 192.168.2.82 eq 20000 (hitcnt=16) 0xd17c91db&lt;/STRONG&gt; 
access-list global_mpc; 1 elements; name hash: 0x2e734f01
access-list global_mpc line 1 extended permit tcp object Internal any eq www (hitcnt=0) 0xc9123e59 
  access-list global_mpc line 1 extended permit tcp 192.168.0.0 255.255.0.0 any eq www (hitcnt=0) 0xc9123e59 
access-list outside_mpc; 1 elements; name hash: 0x57571241
access-list outside_mpc line 1 extended permit tcp any object Internal eq www (hitcnt=1) 0x9b4aa794 
  access-list outside_mpc line 1 extended permit tcp any 192.168.0.0 255.255.0.0 eq www (hitcnt=1) 0x9b4aa794 
access-list outside_access_in; 3 elements; name hash: 0x6892a938
access-list outside_access_in line 1 extended permit tcp any4 any4 object-group outside-access-in-tcp (hitcnt=31) 0x4e5d42fd 
  access-list outside_access_in line 1 extended permit tcp any4 any4 eq 20000 (hitcnt=23) 0xf5151a3c 
  access-list outside_access_in line 1 extended permit tcp any4 any4 eq 8080 (hitcnt=8) 0x7a098f1f 
access-list outside_access_in line 2 extended permit udp any4 any4 object-group outside-access-in-udp (hitcnt=0) 0x0e8e78f6 
  access-list outside_access_in line 2 extended permit udp any4 any4 eq ntp (hitcnt=0) 0x4ecff91a &lt;/PRE&gt;&lt;P&gt;and I also noticed that the&lt;/P&gt;&lt;PRE&gt;policy-map outside-policy
class SFTP-shaping
police input 3000000 5000 conform-action exceed-action drop
police output 3000000 5000 conform-action exceed-action drop&lt;/PRE&gt;&lt;P&gt;is leaving out the "conform-action exceed-action drop" in the running config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br. Soter&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 07:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630541#M1090864</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2022-06-13T07:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630553#M1090865</link>
      <description>&lt;P&gt;Then try the command show service-policy&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 06:55:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630553#M1090865</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-13T06:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630587#M1090866</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;I think we crossed eachother. I have eddited my initial reply with the show service-policy&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 07:53:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4630587#M1090866</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2022-06-13T07:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4631427#M1090922</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;did you see the edited reply with the Show service-policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br. Soter&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 10:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4631427#M1090922</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2022-06-14T10:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4631786#M1090930</link>
      <description>&lt;P&gt;If you are also trying to "police" traffic from the SFTP server then you need to amend your access list to include traffic from this server:&lt;/P&gt;
&lt;P&gt;access-list SFTP extended permit tcp host&amp;nbsp;192.168.2.82 eq 20000 any&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 13:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4631786#M1090930</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-14T13:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Traffic Policing</title>
      <link>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4631836#M1090933</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;of cause man.. so simple. Thanks so much. It working now&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br. Soter&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 14:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-traffic-policing/m-p/4631836#M1090933</guid>
      <dc:creator>Kasper Elsborg</dc:creator>
      <dc:date>2022-06-14T14:10:06Z</dc:date>
    </item>
  </channel>
</rss>

