<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA rate limiting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941042#M1105095</link>
    <description>&lt;P&gt;I have an ASA (5520) with an outside, DMZ, and inside interface and I want to rate limit the traffic (5Mbps) coming from the outside going to a specific server on the DMZ (192.168.3.3).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Never set this up before and it is a live production firewall so would like a sanity check please.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have this configuration -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;asa(config)# access-list WEB_SERVER permit ip any host 192.168.3.3&lt;BR /&gt;asa(config)# class-map Web-Policy &lt;BR /&gt;asa(config-cmap)# match access-list WEB-SERVER&lt;/P&gt;
&lt;P&gt;asa(config)# policy-map WEB &lt;BR /&gt;asa(config-pmap)# class Web-Policy &lt;BR /&gt;asa(config-pmap-c)# police 5000000 conform-action transmit exceed-action drop&lt;/P&gt;
&lt;P&gt;asa(config)# service-policy Web-Policy interface in DMZ&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) will this work ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) is the interface I have applied the service policy to the correct one or should it be the outside interface ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2023 11:39:49 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2023-10-16T11:39:49Z</dc:date>
    <item>
      <title>ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941042#M1105095</link>
      <description>&lt;P&gt;I have an ASA (5520) with an outside, DMZ, and inside interface and I want to rate limit the traffic (5Mbps) coming from the outside going to a specific server on the DMZ (192.168.3.3).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Never set this up before and it is a live production firewall so would like a sanity check please.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have this configuration -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;asa(config)# access-list WEB_SERVER permit ip any host 192.168.3.3&lt;BR /&gt;asa(config)# class-map Web-Policy &lt;BR /&gt;asa(config-cmap)# match access-list WEB-SERVER&lt;/P&gt;
&lt;P&gt;asa(config)# policy-map WEB &lt;BR /&gt;asa(config-pmap)# class Web-Policy &lt;BR /&gt;asa(config-pmap-c)# police 5000000 conform-action transmit exceed-action drop&lt;/P&gt;
&lt;P&gt;asa(config)# service-policy Web-Policy interface in DMZ&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) will this work ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) is the interface I have applied the service policy to the correct one or should it be the outside interface ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 11:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941042#M1105095</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2023-10-16T11:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941044#M1105096</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82310-qos-voip-vpn.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82310-qos-voip-vpn.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check thisb&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 11:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941044#M1105096</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-10-16T11:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941047#M1105097</link>
      <description>&lt;P&gt;yes that should work as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 11:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941047#M1105097</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-10-16T11:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941050#M1105098</link>
      <description>&lt;P&gt;I did, that was the document I used &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wasn't clear to me which interface to apply it to though, I am assuming rate limiting is done outbound by the looks of it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 11:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941050#M1105098</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2023-10-16T11:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941053#M1105099</link>
      <description>&lt;P&gt;""&lt;SPAN&gt;Finally attach the shaping policy to the interface on which to shape and prioritize &lt;STRONG&gt;outbound&lt;/STRONG&gt; traffic""&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As cisco doc. It apply to interface outbound traffic. So it must be outside (nameif).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 11:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941053#M1105099</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-10-16T11:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941056#M1105100</link>
      <description>&lt;P&gt;Looks like OP mentioned DMZ (i think he want to do in DMZ i guess)&lt;/P&gt;
&lt;P&gt;asa(config)# service-policy Web-Policy interface in&lt;STRONG&gt; DMZ&amp;nbsp; ( syntax may be wrong, but that is what his intention i guess)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 12:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941056#M1105100</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-10-16T12:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941214#M1105103</link>
      <description>&lt;P&gt;I want to limit traffic going to a server in the DMZ so I assumed it would either be applied inbound on the outside interface or outbound on the DMZ interface but definitely not inbound on the DMZ interface as far as I can tell.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941214#M1105103</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2023-10-16T16:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA rate limiting</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941216#M1105104</link>
      <description>&lt;P&gt;So outbound would be the DMZ interface in my case as I am not trying to limit traffic to the internet (which most of the examples seem to be about) but limit coming from the internet to a server in the DMZ.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limiting/m-p/4941216#M1105104</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2023-10-16T16:09:09Z</dc:date>
    </item>
  </channel>
</rss>

