<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The problem with most in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737154#M192984</link>
    <description>&lt;P&gt;The problem with most widespread streaming services is that they almost all use Content Delivery Networks (CDNs). The actual content may come from any one of dozens of DNS names and that list changes month-to-month if not day-to-day.&lt;/P&gt;&lt;P&gt;While you can use ACLs with FQDNs and apply that in a class-map and police with a policy-map, it's a very inefficient approach. Plus as Magnus highlighted in his linked article:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px; text-decoration: underline;"&gt;FQDN functionality in ACLs is not a replacement for HTTP Filtering. It cannot distinguish what content is being sent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The current generation&amp;nbsp;of service modules (FirePOWER or the older CX) can do this much more dynamically and with more consistent outcomes.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 16 Aug 2015 18:30:38 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-08-16T18:30:38Z</dc:date>
    <item>
      <title>ASA-5585- How to police Netflix bandwidth for 1Mbps.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737150#M192974</link>
      <description>&lt;P&gt;Hi . We have ASA -5585-X. Lot of Netflix users are consuming bandwidth.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we police Netflix on ASA. I don't want to block it but police it for 1 Mbps.&lt;/P&gt;&lt;P&gt;Please help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Taran&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737150#M192974</guid>
      <dc:creator>tarnhundal</dc:creator>
      <dc:date>2019-03-12T06:24:15Z</dc:date>
    </item>
    <item>
      <title>Hi,Do you have any external</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737151#M192976</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Do you have any external module on this ASA unit ? Like CX etc.&lt;/P&gt;&lt;P&gt;Without these , you would not be able to police this traffic as the classification cannot be done by the ASA device for the Netflix traffic and hence the Policy would not work.&lt;/P&gt;&lt;P&gt;ASA device would be able to use the Regex to match this traffic but that cannot be used with the police command as it can only be used for layer 3 match policies.&lt;/P&gt;&lt;P&gt;For that , you need to check the layer 3 Ip addresses and see if you are able to identity some specific servers for this which is difficult.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2015 13:38:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737151#M192976</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-08-11T13:38:24Z</dc:date>
    </item>
    <item>
      <title>Suggestion:Create a fqdn</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737152#M192980</link>
      <description>&lt;P&gt;Suggestion:&lt;/P&gt;&lt;P&gt;Create a fqdn object matching all netflix domains (if there are multiple)&lt;/P&gt;&lt;P&gt;Create a class-map matching this object&lt;/P&gt;&lt;P&gt;Create a policy-map with the police action for this class&lt;/P&gt;&lt;P&gt;Configure the service-policy on an appropriate interface e.g. outside or inside&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2015 10:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737152#M192980</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2015-08-16T10:56:36Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor, recommended</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737153#M192983</link>
      <description>&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;recommended reading:&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/66011/using-hostnames-dns-access-lists-configuration-steps-caveats-and-troubleshooting&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2015 11:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737153#M192983</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2015-08-16T11:01:14Z</dc:date>
    </item>
    <item>
      <title>The problem with most</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737154#M192984</link>
      <description>&lt;P&gt;The problem with most widespread streaming services is that they almost all use Content Delivery Networks (CDNs). The actual content may come from any one of dozens of DNS names and that list changes month-to-month if not day-to-day.&lt;/P&gt;&lt;P&gt;While you can use ACLs with FQDNs and apply that in a class-map and police with a policy-map, it's a very inefficient approach. Plus as Magnus highlighted in his linked article:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px; text-decoration: underline;"&gt;FQDN functionality in ACLs is not a replacement for HTTP Filtering. It cannot distinguish what content is being sent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The current generation&amp;nbsp;of service modules (FirePOWER or the older CX) can do this much more dynamically and with more consistent outcomes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2015 18:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737154#M192984</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-08-16T18:30:38Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737155#M192985</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thanks for your thoughts! I had to look up the current situation. My idea worked up to 2011, before that date Netflix used two or three cdns with distinguishable DNS names (I found one list of 3 cdn DNS names in a scientific paper, discussing Netflix's caching and cdn architecture), before that (around 2007) they even used anycast (easy to catch with class maps). But this is all obsolete now.&lt;/P&gt;&lt;P&gt;Netflix changed it's cdn architecture in 2011 and is now offering caching servers to IPSs free of charge. According to technical details I have found &lt;A href="http://oc.nflxvideo.net/docs/OpenConnect-Deployment-Guide.pdf"&gt;(link to PDF)&lt;/A&gt; it means that ISPs can set aside one small prefix from their own address space (netflix allows even /31s) for Netflix caching and install the completely preconfigured server, called "OCA" in their network.&lt;/P&gt;&lt;P&gt;The OCA learns through a BGP-session from the ISP which prefixes from the ISPs address pool are allowed to connect to this specific OCA. The learned routes are only used to filter access to the streaming content, not for routing (routing is done with a preconfigured 0.0.0.0/0). The OCA connects to the Netflix cloud control plane and sends the list of allowed prefixes.&lt;/P&gt;&lt;P&gt;Clients (Netflix customers) are directed through this cloud control plane to the IP address of the most appropriate OCA.&lt;/P&gt;&lt;P&gt;Which means, today there's is little chance to catch Netflix traffic with high confidence as ISPs can add additional OCAs with new addresses and most likely no distinguishable DNS domain names.&lt;/P&gt;&lt;P&gt;I think it will be difficult for content filters to catch up with the constantly changing list of OCA IP-addresses unless Netflix publishes it on a regular basis.&lt;/P&gt;&lt;P&gt;So much for policing Netflix...&lt;/P&gt;&lt;P&gt;Best regards, MiKa&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 00:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737155#M192985</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2015-08-17T00:06:14Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,I am agree with you</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737156#M192986</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;I am agree with you. I tried lot of other things. I tried regex but nothing worked. Netflix has many servers which offer streaming. So I tried to find those IPs what I could&amp;nbsp;and created ACL to match those IPs and then bind with QOS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen some improvement but not the satisfactory result. Even after we decided to drop whole Netflix traffic but still some of its traffic was leaking.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I put DNS resolution of netflix to 127.1.1.1 and we found the desired result &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I came through some of Cisco docs mentioning without external modules/ CX we can't handle https in desired manner.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Taran&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 21:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-how-to-police-netflix-bandwidth-for-1mbps/m-p/2737156#M192986</guid>
      <dc:creator>tarnhundal</dc:creator>
      <dc:date>2015-08-19T21:45:59Z</dc:date>
    </item>
  </channel>
</rss>

