<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help - ASA 5525 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-asa-5525/m-p/2864551#M154736</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm setting up rate limiting on an ASA with the police command.&amp;nbsp; I can't seem to find if this is a&amp;nbsp; per host basis or if my entire group will be limited to the set threshold.&amp;nbsp; If I use an ACL to include RFC 1918 and permit the rate limit on the inside interface outbound and set police to 10000000 will that include the entire object group or will that be on a per ip basis within the range?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My goal is to limit on a per user or IP basis to 10Mb.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;object-group network RATE_LIMIT_PERMIT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;&amp;nbsp; group-object RFC_1918&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; access-list RATE_LIMIT_INTERNET_TRAFFIC extended permit ip object-group RATE_LIMIT_PERMIT any&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;&lt;STRONG&gt; &lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;class-map RATE_LIMIT_INET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; match access-list RATE_LIMIT_INTERNET_TRAFFIC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;policy-map RATE_LIMIT_INET_POLICY&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; class RATE_LIMIT_INET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; police output 10000000 1875000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;service-policy RATE_LIMIT_INET_POLICY interface inside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;Ron&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:37:55 GMT</pubDate>
    <dc:creator>ron.pickar</dc:creator>
    <dc:date>2019-03-12T07:37:55Z</dc:date>
    <item>
      <title>Help - ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/help-asa-5525/m-p/2864551#M154736</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm setting up rate limiting on an ASA with the police command.&amp;nbsp; I can't seem to find if this is a&amp;nbsp; per host basis or if my entire group will be limited to the set threshold.&amp;nbsp; If I use an ACL to include RFC 1918 and permit the rate limit on the inside interface outbound and set police to 10000000 will that include the entire object group or will that be on a per ip basis within the range?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My goal is to limit on a per user or IP basis to 10Mb.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;object-group network RATE_LIMIT_PERMIT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;&amp;nbsp; group-object RFC_1918&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; access-list RATE_LIMIT_INTERNET_TRAFFIC extended permit ip object-group RATE_LIMIT_PERMIT any&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;&lt;STRONG&gt; &lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;class-map RATE_LIMIT_INET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; match access-list RATE_LIMIT_INTERNET_TRAFFIC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;policy-map RATE_LIMIT_INET_POLICY&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; class RATE_LIMIT_INET&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt; police output 10000000 1875000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;service-policy RATE_LIMIT_INET_POLICY interface inside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;Ron&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:37:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-asa-5525/m-p/2864551#M154736</guid>
      <dc:creator>ron.pickar</dc:creator>
      <dc:date>2019-03-12T07:37:55Z</dc:date>
    </item>
    <item>
      <title>if you want per user</title>
      <link>https://community.cisco.com/t5/network-security/help-asa-5525/m-p/2864552#M154737</link>
      <description>&lt;P&gt;if you want per user limitation so you must make ACL for each user and class-map for each user&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 01:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-asa-5525/m-p/2864552#M154737</guid>
      <dc:creator>Tagir Temirgaliyev</dc:creator>
      <dc:date>2016-04-19T01:32:16Z</dc:date>
    </item>
    <item>
      <title>That was my fear.  That will</title>
      <link>https://community.cisco.com/t5/network-security/help-asa-5525/m-p/2864553#M154738</link>
      <description>&lt;P&gt;That was my fear.&amp;nbsp; That will be too much overhead to create. Is there a better option to limit on a per user basis within the ASA?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ron&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 13:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-asa-5525/m-p/2864553#M154738</guid>
      <dc:creator>ron.pickar</dc:creator>
      <dc:date>2016-04-19T13:13:52Z</dc:date>
    </item>
  </channel>
</rss>

