<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD QoS interface selection best practice in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372238#M1124562</link>
    <description>&lt;P&gt;If you source the outside zone, doesn’t this mean the connection must initiate from the outside for the QoS rule to apply? I suppose that’s ok for rate limiting traffic initiated from the outside.&lt;/P&gt;
&lt;P&gt;May above question was an example rate limiting connections initiated from the inside to the outside and discussing which interface to apply the rating limiting on ie source or destination interface.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Feb 2026 13:50:43 GMT</pubDate>
    <dc:creator>Jack G</dc:creator>
    <dc:date>2026-02-24T13:50:43Z</dc:date>
    <item>
      <title>FTD QoS interface selection best practice</title>
      <link>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372039#M1124549</link>
      <description>&lt;P&gt;So I created a test rule to limited downloads for anything in the inside zone from outside zone (internet). If I select apply on destination or source interface it basically does the same rate limiting, which I think is ok. Does it really matter which interface I select for such a configuration? Should I use destination interface since it’s the closest to the internet server..?&lt;/P&gt;
&lt;P&gt;For source interface objects I’m using inside zone and for destination interface objects I’m using outside zone. Rate is 10mbps up and down.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 00:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372039#M1124549</guid>
      <dc:creator>Jack G</dc:creator>
      <dc:date>2026-02-24T00:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD QoS interface selection best practice</title>
      <link>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372123#M1124552</link>
      <description>&lt;P&gt;i select outside zone to inside zone (source interface Outside)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The FMC's quality of service is "policing" (dropping packets), not "shaping" (buffering them). For TCP downloads, this will cause the sender to slow down naturally, but it can be "choppy" for UDP streams like video calls&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 08:08:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372123#M1124552</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-02-24T08:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: FTD QoS interface selection best practice</title>
      <link>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372238#M1124562</link>
      <description>&lt;P&gt;If you source the outside zone, doesn’t this mean the connection must initiate from the outside for the QoS rule to apply? I suppose that’s ok for rate limiting traffic initiated from the outside.&lt;/P&gt;
&lt;P&gt;May above question was an example rate limiting connections initiated from the inside to the outside and discussing which interface to apply the rating limiting on ie source or destination interface.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 13:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372238#M1124562</guid>
      <dc:creator>Jack G</dc:creator>
      <dc:date>2026-02-24T13:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD QoS interface selection best practice</title>
      <link>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372284#M1124567</link>
      <description>&lt;P&gt;But when you initiate the connection from inside to outside, the download will be outside to inside, that is the best I can think of to limit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;For a download (Internet&amp;nbsp;&amp;nbsp;Inside), the "Destination Interface" is your&amp;nbsp;Inside Interface. By applying the limit here, you control traffic as it&amp;nbsp;&lt;EM class="eujQNb" data-complete="true"&gt;exits&lt;/EM&gt;&amp;nbsp;the firewall toward your users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 15:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-qos-interface-selection-best-practice/m-p/5372284#M1124567</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-02-24T15:53:27Z</dc:date>
    </item>
  </channel>
</rss>

