<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA QoS question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271138#M350703</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you wanted to say DSCP instead of DHCP value but you got it &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with the configuration shown above you will create a priority queue just for traffic that has the DSCP Expedited forwarding value&amp;nbsp; (46) set on&amp;nbsp; the IP header , and besides that, it must go over the VPN remote access tunnel group call tunnel-grp1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 May 2013 21:04:55 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-05-02T21:04:55Z</dc:date>
    <item>
      <title>ASA QoS question</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271134#M350698</link>
      <description>&lt;P&gt;I'm trying to better understand what the shape average command does in the following config?&amp;nbsp; Assume that my Internet upload bandwidth is approximately 6Mbps and that I'd like to give priority to my voice traffic egressing the ASA.&amp;nbsp; Another thing I'm unclear on is what if my voice traffic uses a site to site tunnel?&amp;nbsp; Does the shaping below even work if voice traffic is being tunneled to the main office?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed that running speedtest.net with the current config shows approximately 1Mbps upload speed.&amp;nbsp; Changing shape average to 4000000 changes the upload speed results to 4Mbps and so on so it's doing something, but exactly what I'm still unsure.&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map my-voice&lt;BR /&gt;match dscp ef &lt;BR /&gt;!&lt;BR /&gt;policy-map priority-policy&lt;BR /&gt;class my-voice&lt;BR /&gt;&amp;nbsp; priority&lt;BR /&gt;policy-map shape-priority-policy&lt;BR /&gt;class class-default&lt;BR /&gt;&amp;nbsp; shape average 1000000&lt;BR /&gt;&amp;nbsp; service-policy priority-policy&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;service-policy shape-priority-policy interface outside&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271134#M350698</guid>
      <dc:creator>david</dc:creator>
      <dc:date>2019-03-12T01:37:28Z</dc:date>
    </item>
    <item>
      <title>ASA QoS question</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271135#M350699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the doc for sample configs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-1230"&gt;https://supportforums.cisco.com/docs/DOC-1230&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 01:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271135#M350699</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2013-05-02T01:03:27Z</dc:date>
    </item>
    <item>
      <title>ASA QoS question</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271136#M350700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic shaping does not give priority, its usage it completely different.&lt;/P&gt;&lt;P&gt;See the command reference for more information.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s1.html#wp1427655"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s1.html#wp1427655&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For VPN you need to match the tunnel-group as shown in the above reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Felipe &lt;/P&gt;&lt;P&gt;Security Team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 01:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271136#M350700</guid>
      <dc:creator>lcambron</dc:creator>
      <dc:date>2013-05-02T01:10:59Z</dc:date>
    </item>
    <item>
      <title>ASA QoS question</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271137#M350701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Based on the link above, it appears that shaping and &lt;STRONG&gt;priority &lt;/STRONG&gt;for voice is what I'm doing? Seems like the only thing I was missing was the &lt;EM&gt;match tunnel-group &lt;/EM&gt;command.&amp;nbsp; I also have "priority-queue outside" in my config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1 id="Traffic_Shaping_with_Prioritization"&gt;Traffic Shaping with Prioritization&lt;/H1&gt;&lt;P&gt;Now, lets assume that we have the same ASA as in the previous case. And we now want to traffic shape all traffic and prioritize the voice through the VPN. In other words we will traffic shape all traffic for 900kbps, prioritize the voice and guarantee 100kbps for it. Again, we assume that the voice traffic is flagged with dhcp field ef and the tunnel group name is tunnel-grp1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;&lt;PRE&gt;ASA(config)# priority-queue outside&lt;BR /&gt;&lt;BR /&gt;ASA(config)# class-map TG1-voice-class&lt;BR /&gt;ASA(config-cmap)# match tunnel-group tunnel-grp1&lt;BR /&gt;ASA(config-cmap)# match dscp ef&lt;BR /&gt;&lt;BR /&gt;ASA(config-cmap)# policy-map priority-policy&lt;BR /&gt;ASA(config-pmap)# class TG1-voice-class&lt;BR /&gt;ASA(config-pmap-c)# priority&lt;BR /&gt;&lt;BR /&gt;ASA(config-pmap-c)# policy-map shape-priority-policy&lt;BR /&gt;ASA(config-pmap)# class class-default&lt;BR /&gt;ASA(config-pmap-c)# shape average 900000&lt;BR /&gt;ASA(config-pmap-c)# service-policy priority-policy&lt;BR /&gt;&lt;BR /&gt;ASA(config-pmap-c)# service-policy shape-priority-policy interface outside&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 19:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271137#M350701</guid>
      <dc:creator>david</dc:creator>
      <dc:date>2013-05-02T19:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA QoS question</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271138#M350703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you wanted to say DSCP instead of DHCP value but you got it &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with the configuration shown above you will create a priority queue just for traffic that has the DSCP Expedited forwarding value&amp;nbsp; (46) set on&amp;nbsp; the IP header , and besides that, it must go over the VPN remote access tunnel group call tunnel-grp1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 21:04:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271138#M350703</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-02T21:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA QoS question</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271139#M350705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Julio.&amp;nbsp; Yeah, that was copied from the linked article above and yes, they meant to say DSCP.&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the only thing I'm unclear on is what happens to available bandwidth when you have 6Mbps upload and apply different shape averages?&amp;nbsp; In the referenced article, they state that they have 1Mbps upload speed and by using shape average = 900000, they say 100Kbps is left over and/or guaranteed for voice.&amp;nbsp; Does that mean that if I have 6Mbps upload speed and use shape average = 4000000, I'm prioritizing voice (DSCP - 46) and also guaranteeing approximately 2Mbps to voice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 22:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271139#M350705</guid>
      <dc:creator>david</dc:creator>
      <dc:date>2013-05-02T22:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA QoS question</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271140#M350707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will be providing priority to what's left and if matches the traffic patterns you set on the class-map&amp;nbsp; ofcourse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 22:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-question/m-p/2271140#M350707</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-02T22:54:30Z</dc:date>
    </item>
  </channel>
</rss>

