<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA rate limit downloads from internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413678#M309704</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response, would the following work in my situation?&lt;/P&gt;&lt;P&gt;I don't have a problem configuring it, but I want to know that I am thinking about this correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have 10Mbit upload and 20Mbit download from my ISP.&lt;/P&gt;&lt;P&gt;I have 2 internal subnets:&lt;/P&gt;&lt;P&gt;10.10.10.0/24 -&amp;gt; I want to limit upload to 5Mbit and download to 10Mbit&lt;/P&gt;&lt;P&gt;10.20.20.0/24 -&amp;gt; I want to limit upoad to 7Mbit and download to 15Mbit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I apply the following to my Outside interface (creating 4 policys):&lt;/P&gt;&lt;P&gt;1.1) police upload traffic subnet 1&lt;/P&gt;&lt;P&gt;ACL src = 10.10.10.0/24 | dest = any&lt;/P&gt;&lt;P&gt;Police outbound = 5Mbit&lt;/P&gt;&lt;P&gt;1.2) police download traffic subnet 1&lt;/P&gt;&lt;P&gt;ACL src = any | dest = 10.10.10.0/24&lt;/P&gt;&lt;P&gt;Police inbound = 10Mbit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.1) police upload traffic subnet 2&lt;/P&gt;&lt;P&gt;ACL src = 10.20.20.0/24 | dest = any&lt;/P&gt;&lt;P&gt;Police outbound = 7Mbit&lt;/P&gt;&lt;P&gt;112) police download traffic subnet 2&lt;/P&gt;&lt;P&gt;ACL src = any | dest = 10.20.20.0/24&lt;/P&gt;&lt;P&gt;Police inbound = 15Mbit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this work?&lt;/P&gt;&lt;P&gt;Won't I run into issues with NAT/PAT concerning my ACL's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Nov 2013 14:18:05 GMT</pubDate>
    <dc:creator>guy tec</dc:creator>
    <dc:date>2013-11-04T14:18:05Z</dc:date>
    <item>
      <title>ASA rate limit downloads from internet</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413676#M309701</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco ASA 5512 that sits between my LAN and the internet (all traffic is natted/patted to the outside).&lt;/P&gt;&lt;P&gt;I have multiple subnets, each subnet has its own VLAN, and sub interface on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I want to overcome that one of my subnets can fill the whole internet pipe (both download from the internet and upload to the internet)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understand it correctly I can do this with a service policy that does policing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my question, on what interface do I need to apply the policy? and what kind of policing do I need, inbound and/or outbound?&lt;/P&gt;&lt;P&gt;Do I need 2 policys, one for the download limiting, one for the upload limiting?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:59:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413676#M309701</guid>
      <dc:creator>guy tec</dc:creator>
      <dc:date>2019-03-12T02:59:48Z</dc:date>
    </item>
    <item>
      <title>ASA rate limit downloads from internet</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413677#M309702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can use policing for that. It&lt;SPAN style="font-size: 10pt;"&gt; can be done both in the inbound and outbound direction:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/mpf_service_policy.html#wp1162717"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/mpf_service_policy.html#wp1162717&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Here is an example on how to activate it:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/conns_qos.html#wp1221898"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/conns_qos.html#wp1221898&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 12:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413677#M309702</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-11-04T12:35:00Z</dc:date>
    </item>
    <item>
      <title>ASA rate limit downloads from internet</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413678#M309704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response, would the following work in my situation?&lt;/P&gt;&lt;P&gt;I don't have a problem configuring it, but I want to know that I am thinking about this correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have 10Mbit upload and 20Mbit download from my ISP.&lt;/P&gt;&lt;P&gt;I have 2 internal subnets:&lt;/P&gt;&lt;P&gt;10.10.10.0/24 -&amp;gt; I want to limit upload to 5Mbit and download to 10Mbit&lt;/P&gt;&lt;P&gt;10.20.20.0/24 -&amp;gt; I want to limit upoad to 7Mbit and download to 15Mbit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I apply the following to my Outside interface (creating 4 policys):&lt;/P&gt;&lt;P&gt;1.1) police upload traffic subnet 1&lt;/P&gt;&lt;P&gt;ACL src = 10.10.10.0/24 | dest = any&lt;/P&gt;&lt;P&gt;Police outbound = 5Mbit&lt;/P&gt;&lt;P&gt;1.2) police download traffic subnet 1&lt;/P&gt;&lt;P&gt;ACL src = any | dest = 10.10.10.0/24&lt;/P&gt;&lt;P&gt;Police inbound = 10Mbit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.1) police upload traffic subnet 2&lt;/P&gt;&lt;P&gt;ACL src = 10.20.20.0/24 | dest = any&lt;/P&gt;&lt;P&gt;Police outbound = 7Mbit&lt;/P&gt;&lt;P&gt;112) police download traffic subnet 2&lt;/P&gt;&lt;P&gt;ACL src = any | dest = 10.20.20.0/24&lt;/P&gt;&lt;P&gt;Police inbound = 15Mbit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this work?&lt;/P&gt;&lt;P&gt;Won't I run into issues with NAT/PAT concerning my ACL's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 14:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413678#M309704</guid>
      <dc:creator>guy tec</dc:creator>
      <dc:date>2013-11-04T14:18:05Z</dc:date>
    </item>
    <item>
      <title>ASA rate limit downloads from internet</title>
      <link>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413679#M309707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that's a way it can be implemented. You could think about using a service-policy on the inside interface for outgoing traffic because it doesn't make any sense to first process the traffic in the ASA and later to drop it on the outside interface. But with your ASA you probably won't run into any performance problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT/PAT is handled transparently in your ASA-version. That was different in the versions &amp;lt; 8.3, but these are not available for your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 15:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-rate-limit-downloads-from-internet/m-p/2413679#M309707</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-11-04T15:07:54Z</dc:date>
    </item>
  </channel>
</rss>

