<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908450#M153508</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;For now, i just want to police trafic that come from internal network and that go to external network...&lt;/P&gt;
&lt;P&gt;Franck&lt;/P&gt;</description>
    <pubDate>Fri, 27 May 2016 07:39:56 GMT</pubDate>
    <dc:creator>n.franck</dc:creator>
    <dc:date>2016-05-27T07:39:56Z</dc:date>
    <item>
      <title>Traffic Policing at bad rates</title>
      <link>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908448#M153506</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;It's my first post at the cisco&amp;nbsp;community. So as you will see, i'm not very fluent in English.&lt;/P&gt;
&lt;P&gt;I have a couple of 5515 ASA (9.1(2) software) in active/passive failover.&lt;/P&gt;
&lt;P&gt;In the past, i have configured the traffic to be policed at 500 Mbs and it worked fine.now I want to police incoming traffic at 370 Mbs and it don't works.&lt;/P&gt;
&lt;P&gt;Regardless of police configuration, the asa continue to police at 500 mbs. However the police traffic seem to work:&lt;/P&gt;
&lt;P&gt;FWCLI1# sh service police&lt;/P&gt;
&lt;P&gt;Interface office:&lt;BR /&gt;&amp;nbsp; Service-policy: office-policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: office-class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Input police Interface office:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cir 370000000 bps, bc 185000 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conformed 12088008714 packets, 16534894809058 bytes; actions:&amp;nbsp; transmit&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; exceeded 409706800 packets, 580106518335 bytes; actions:&amp;nbsp; drop&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conformed 115580664 bps, exceed 4055000 bps&lt;/P&gt;
&lt;P&gt;Interface Beemo:&lt;BR /&gt;&amp;nbsp; Service-policy: Beemo-policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: Beemo-class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output police Interface Beemo:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cir 370000000 bps, bc 185000 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conformed 12059578807 packets, 16493581309971 bytes; actions:&amp;nbsp; transmit&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; exceeded 57232 packets, 80699078 bytes; actions:&amp;nbsp; drop&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conformed 115291880 bps, exceed 560 bps&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For better comprehension, office interface is outside interface and BEEMO interface is inside interface and i implement policing traffic at 2 interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My cacti server indicate me that the traffic climb to 600&amp;nbsp; Mbs at outside interface and 500 Mb at inside interface as you can see in png attachements.&lt;/P&gt;
&lt;P&gt;this amount of traffic is confirmed by my isp so i think that problem don't come from cacti server.&lt;/P&gt;
&lt;P&gt;Does any one could help me ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908448#M153506</guid>
      <dc:creator>n.franck</dc:creator>
      <dc:date>2019-03-26T00:58:48Z</dc:date>
    </item>
    <item>
      <title>Hi -</title>
      <link>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908449#M153507</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;
&lt;P&gt;Both of your police&amp;nbsp;policies need to be "output".&amp;nbsp; Currently you are only policing traffic in a unidirectional manner.&amp;nbsp; By setting both police policies to output you will match traffic in both directions and drop as needed.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;PSC&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 21:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908449#M153507</guid>
      <dc:creator>Paul Chapman</dc:creator>
      <dc:date>2016-05-26T21:09:14Z</dc:date>
    </item>
    <item>
      <title>Hello</title>
      <link>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908450#M153508</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;For now, i just want to police trafic that come from internal network and that go to external network...&lt;/P&gt;
&lt;P&gt;Franck&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 07:39:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908450#M153508</guid>
      <dc:creator>n.franck</dc:creator>
      <dc:date>2016-05-27T07:39:56Z</dc:date>
    </item>
    <item>
      <title>Hi Franck -</title>
      <link>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908451#M153509</link>
      <description>&lt;P&gt;Hi Franck -&lt;/P&gt;
&lt;P&gt;I found a&amp;nbsp;few interesting things in the documentation. 1) If a flow is established before the policer is installed, then you have to do a "clear conn" to get the&amp;nbsp;new policy to apply. 2) Only outbound policers can be applied to VPN tunneled traffic.&lt;/P&gt;
&lt;P&gt;Considering these 2 cases, have you rebooted the firewall lately? Are you trying to&amp;nbsp;limit traffic to a VPN destination?&lt;/P&gt;
&lt;P&gt;PSC&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 17:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-policing-at-bad-rates/m-p/2908451#M153509</guid>
      <dc:creator>Paul Chapman</dc:creator>
      <dc:date>2016-05-27T17:15:55Z</dc:date>
    </item>
  </channel>
</rss>

