<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rate limiting FTD's own traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897115#M1103150</link>
    <description>&lt;P&gt;Aasume you have upload 100 and download 500 and you want to give 25% to VoIP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you can try add to QoS policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One for app VoIP give it 25 and 125&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And other for any IP give 75 and 375.&lt;/P&gt;
&lt;P&gt;I am not sure it work but I dont think fpr have QoS like router and SW.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2023 17:16:04 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-08-01T17:16:04Z</dc:date>
    <item>
      <title>Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896421#M1103122</link>
      <description>&lt;P&gt;Is there a way to rate limit the traffic generated by the FTD itself?&amp;nbsp;&amp;nbsp;Example: if VoIP is going through the Firewall, can we prioritize VoIP over the events traffic generated by the FTD itself?&lt;/P&gt;
&lt;P&gt;I'm familiar with the QoS feature of FTD which permit basic rate limitation by assigning maximum throughput on user traffic.&amp;nbsp; Is there a way we could use the FTD QoS feature to limit the outbound traffic a FTD is sending to the FMC, by, example limiting the traffic to FMC TCP/8305?&lt;/P&gt;
&lt;P&gt;Or is the FTD like the ASA: It filters user traffic, but not the traffic generated by the FTD itself?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 23:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896421#M1103122</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2023-07-31T23:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896432#M1103123</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The feature you mean would be Control Plane Policing (CoPP), that is something that does exist on Cisco IOS, but it is not relevant to FTD.&lt;/P&gt;
&lt;P&gt;The FTD has build-in control to protect it's control plane, the QoS rate limit you mean would affect the data plane.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 00:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896432#M1103123</guid>
      <dc:creator>rhingel</dc:creator>
      <dc:date>2023-08-01T00:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896974#M1103139</link>
      <description>&lt;P&gt;Could you expand on the built-in control plane mechanisms in FTD to prevent overloading the system?&lt;/P&gt;
&lt;P&gt;A more drastic approach, which would not be useful, but does provide strict control-plane control is using FlexConfig with the access-group xxxx&amp;nbsp; control-plane command.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 13:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896974#M1103139</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2023-08-01T13:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896981#M1103140</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291184"&gt;@cpaquet&lt;/a&gt; I am not aware of rate-limiting availability on the FTD control plane, but if you used a dedicated management interface instead of a data interface for communication to/from the FMC, then that management event traffic would be isolated.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 13:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896981#M1103140</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-01T13:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896983#M1103141</link>
      <description>&lt;P&gt;I am trying to think of an use case where you need to rate-limit the communication between the FTD and FMC, can you ellaborate on your requirement?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 13:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896983#M1103141</guid>
      <dc:creator>rhingel</dc:creator>
      <dc:date>2023-08-01T13:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896989#M1103142</link>
      <description>&lt;P&gt;Hi'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are two QoS'&lt;/P&gt;
&lt;P&gt;QoS of VoIP pass through FTD which applies to interface&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But how QoS of VoIP generate from FTD itself? That you need to elaborate.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 14:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4896989#M1103142</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-08-01T14:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897098#M1103148</link>
      <description>&lt;P&gt;Example: In a data center (clustering, LISP, etc), where you are doing extension FTD logging to the FMC, but also you have multiple critical user applications.&amp;nbsp; How would you configured the FTD to give precedence to user applications if there is contation for the bandwidht?&amp;nbsp; Thus the possible need to throttling the FTD 'self-traffic'.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 16:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897098#M1103148</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2023-08-01T16:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897099#M1103149</link>
      <description>&lt;P&gt;Good point.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 16:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897099#M1103149</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2023-08-01T16:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897115#M1103150</link>
      <description>&lt;P&gt;Aasume you have upload 100 and download 500 and you want to give 25% to VoIP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you can try add to QoS policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One for app VoIP give it 25 and 125&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And other for any IP give 75 and 375.&lt;/P&gt;
&lt;P&gt;I am not sure it work but I dont think fpr have QoS like router and SW.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 17:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897115#M1103150</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-08-01T17:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897131#M1103151</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291184"&gt;@cpaquet&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Example: In a data center (clustering, LISP, etc), where you are doing extension FTD logging to the FMC&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291184"&gt;@cpaquet&lt;/a&gt; you can rate limit syslog traffic, this can be configured via platform settings policy and deployed to the managed FTD. &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html#toc-hId--41694258" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html#toc-hId--41694258&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I believe QoS will only apply to traffic "through" the FTD, not "to" (traffic to/from the FTD itself).&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 17:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897131#M1103151</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-01T17:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897137#M1103152</link>
      <description>&lt;P&gt;He is confused about data pass or initiate from FTD. I think meaning pass through ftd so he need qos policy.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 17:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897137#M1103152</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-08-01T17:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897234#M1103158</link>
      <description>&lt;P&gt;Hi Rob, excellent suggestion to use syslog rate limit, if throttling for FTD 'self-traffic' is not available.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 20:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897234#M1103158</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2023-08-01T20:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting FTD's own traffic</title>
      <link>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897235#M1103159</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;: Rob is not confused.&amp;nbsp; He understand perfectly my original question which is: how can we throttling the traffic generated by FTD itself. This is considered traffic 'to/from' the firewall, and not traffic through the firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 20:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rate-limiting-ftd-s-own-traffic/m-p/4897235#M1103159</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2023-08-01T20:51:58Z</dc:date>
    </item>
  </channel>
</rss>

