<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA QoS Priority in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261540#M357401</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;i have one question!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i established VPN between 2 sites allowing VOIP thru the tunnel&lt;/P&gt;&lt;P&gt;my internet speed is 4Mbps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want to give priority for VOIP and E-mail (SMTP,POP3) during congestion while dropping other packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does my Configuration fit my scenario ? does this mean when congestion occur, priority traffic while transmit First ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 1 extended permit tcp x.x.x.x 255.255.255.0 any eq smtp (hitcnt=3) 0x82c5c9dc&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 2 extended permit tcp x.x.x.x 255.255.255.0 any eq 587 (hitcnt=12) 0xa01c0a77&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 3 extended permit tcp xxxxx 255.255.255.0 any eq pop3 (hitcnt=71) 0x49e769fb&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 4 extended permit tcp xxxxx.0 255.255.255.0 any eq 993 (hitcnt=5) 0xdc9da253&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 5 extended permit tcp xxxxx 255.255.255.0 any eq 995 (hitcnt=0) 0x19722cfa&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 6 extended permit tcp xxxxx 255.255.255.0 any eq imap4 (hitcnt=692) 0xa6255182&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE; 8 elements; name hash: 0x317acd62&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE line 1 extended permit udp xxxxxx 255.255.255.0 eq sip host 192.168.2.100 (hitcnt=0) 0x4eb1b7b0&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE line 2 extended permit udp xxxxxx 255.255.255.0 range 16384 32767 host 192.168.10.100 (hitcnt=0) 0xe05393fc&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE line 3 extended permit udp xxxxx 255.255.255.0 eq sip host 192.168.10.100 (hitcnt=0) 0xed1bb356&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map e-mail-qos&lt;/P&gt;&lt;P&gt; match access-list e-mail-qos&lt;/P&gt;&lt;P&gt;class-map voice_traffic&lt;/P&gt;&lt;P&gt; match access-list REMARK-DSCP-VOICE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map QoS&lt;/P&gt;&lt;P&gt; class voice_traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt; class e-mail-qos&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; police output 4000000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;priority-queue outside&lt;/P&gt;&lt;P&gt;&amp;nbsp; queue-limit&amp;nbsp;&amp;nbsp; 512&lt;/P&gt;&lt;P&gt;&amp;nbsp; tx-ring-limit 128&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:50:01 GMT</pubDate>
    <dc:creator>mohdkadie</dc:creator>
    <dc:date>2019-03-12T01:50:01Z</dc:date>
    <item>
      <title>ASA QoS Priority</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261540#M357401</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;i have one question!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i established VPN between 2 sites allowing VOIP thru the tunnel&lt;/P&gt;&lt;P&gt;my internet speed is 4Mbps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want to give priority for VOIP and E-mail (SMTP,POP3) during congestion while dropping other packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does my Configuration fit my scenario ? does this mean when congestion occur, priority traffic while transmit First ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 1 extended permit tcp x.x.x.x 255.255.255.0 any eq smtp (hitcnt=3) 0x82c5c9dc&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 2 extended permit tcp x.x.x.x 255.255.255.0 any eq 587 (hitcnt=12) 0xa01c0a77&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 3 extended permit tcp xxxxx 255.255.255.0 any eq pop3 (hitcnt=71) 0x49e769fb&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 4 extended permit tcp xxxxx.0 255.255.255.0 any eq 993 (hitcnt=5) 0xdc9da253&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 5 extended permit tcp xxxxx 255.255.255.0 any eq 995 (hitcnt=0) 0x19722cfa&lt;/P&gt;&lt;P&gt;access-list e-mail-qos line 6 extended permit tcp xxxxx 255.255.255.0 any eq imap4 (hitcnt=692) 0xa6255182&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE; 8 elements; name hash: 0x317acd62&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE line 1 extended permit udp xxxxxx 255.255.255.0 eq sip host 192.168.2.100 (hitcnt=0) 0x4eb1b7b0&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE line 2 extended permit udp xxxxxx 255.255.255.0 range 16384 32767 host 192.168.10.100 (hitcnt=0) 0xe05393fc&lt;/P&gt;&lt;P&gt;access-list REMARK-DSCP-VOICE line 3 extended permit udp xxxxx 255.255.255.0 eq sip host 192.168.10.100 (hitcnt=0) 0xed1bb356&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map e-mail-qos&lt;/P&gt;&lt;P&gt; match access-list e-mail-qos&lt;/P&gt;&lt;P&gt;class-map voice_traffic&lt;/P&gt;&lt;P&gt; match access-list REMARK-DSCP-VOICE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map QoS&lt;/P&gt;&lt;P&gt; class voice_traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt; class e-mail-qos&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; police output 4000000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;priority-queue outside&lt;/P&gt;&lt;P&gt;&amp;nbsp; queue-limit&amp;nbsp;&amp;nbsp; 512&lt;/P&gt;&lt;P&gt;&amp;nbsp; tx-ring-limit 128&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:50:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261540#M357401</guid>
      <dc:creator>mohdkadie</dc:creator>
      <dc:date>2019-03-12T01:50:01Z</dc:date>
    </item>
    <item>
      <title>ASA QoS Priority</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261541#M357402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the ACL for voip traffic should include both directions, so you sould add reverse entries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, wich looks better to me, you can match voip traffic in the class map using dscp bit. Smth like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map VOIP&lt;/P&gt;&lt;P&gt; match dscp ef&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For email-related traffic it's ok.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 07:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261541#M357402</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-05-28T07:42:06Z</dc:date>
    </item>
    <item>
      <title>ASA QoS Priority</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261542#M357403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Plus, cause priority queuing works only in outbound direction, you should apply (at least for voin) the policy map on both interfaces, or globaly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 07:53:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261542#M357403</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-05-28T07:53:23Z</dc:date>
    </item>
    <item>
      <title>ASA QoS Priority</title>
      <link>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261543#M357404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;actually i applied the QoS in the outside (outbound) direction &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i guess everything is working fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 08:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-qos-priority/m-p/2261543#M357404</guid>
      <dc:creator>mohdkadie</dc:creator>
      <dc:date>2013-05-28T08:04:47Z</dc:date>
    </item>
  </channel>
</rss>

