<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic low-latency prio queue for udp traffic, but not matching ACL? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851096#M459625</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The asa had rebooted due to a power failure, so now hitcount=0 (although the vpn works as expected).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you propose I do a capture based on my ACL (which doesnt have any hit count), or should I create a capture with port 1194/udp on interface outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some stats:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa# show access-list&amp;nbsp; | inc priority&lt;/P&gt;&lt;P&gt;access-list priority line 1 extended permit udp any any eq 1194 (hitcnt=0) 0xbbdd01d4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa# sh service-policy&lt;/P&gt;&lt;P&gt;Global policy: &lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: QoS_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: priotraffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface outside: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface inside: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface mobenga: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface escom: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface management: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface server: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface vpn: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface cafe_member: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class-default&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Feb 2012 08:41:03 GMT</pubDate>
    <dc:creator>3moloz123</dc:creator>
    <dc:date>2012-02-13T08:41:03Z</dc:date>
    <item>
      <title>low-latency prio queue for udp traffic, but not matching ACL?</title>
      <link>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851094#M459623</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an OpenVPN service running behind an ASA for which I would like to prioritize the packets.&lt;/P&gt;&lt;P&gt;The OpenVPN service connects to a remote OpenVPN service on 1194/udp, and accepts traffic on udp/1194 for yet another OpenVPN server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what I did:&lt;/P&gt;&lt;P&gt;access-list priority extended permit udp any any eq 1194&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;priority-queue outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map priotraffic&lt;/P&gt;&lt;P&gt; match access-list priority&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map QoS_policy&lt;/P&gt;&lt;P&gt; class priotraffic&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy QoS_policy global&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;priority-queue outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are hundreds of packets per second on this OpenVPN, but still I only see 2 matched packets on the ACL "priority":&lt;/P&gt;&lt;P&gt;# show access-list | inc priority&lt;/P&gt;&lt;P&gt;access-list priority line 1 extended permit udp any any eq 1194 (hitcnt=2) 0xbbdd01d4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something? Must I know both src AND destination ports in order to achieve this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851094#M459623</guid>
      <dc:creator>3moloz123</dc:creator>
      <dc:date>2019-03-11T22:27:36Z</dc:date>
    </item>
    <item>
      <title>low-latency prio queue for udp traffic, but not matching ACL?</title>
      <link>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851095#M459624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nop, the ACL its properly configured, you do not need to set the source port!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do a capture on the ASA do you see more than 2 packets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens if you do sh service-policy?&lt;/P&gt;&lt;P&gt;How much packets do you see in the service policy you configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all helpful posts!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 17:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851095#M459624</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-10T17:26:14Z</dc:date>
    </item>
    <item>
      <title>low-latency prio queue for udp traffic, but not matching ACL?</title>
      <link>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851096#M459625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The asa had rebooted due to a power failure, so now hitcount=0 (although the vpn works as expected).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you propose I do a capture based on my ACL (which doesnt have any hit count), or should I create a capture with port 1194/udp on interface outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some stats:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa# show access-list&amp;nbsp; | inc priority&lt;/P&gt;&lt;P&gt;access-list priority line 1 extended permit udp any any eq 1194 (hitcnt=0) 0xbbdd01d4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa# sh service-policy&lt;/P&gt;&lt;P&gt;Global policy: &lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: QoS_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: priotraffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface outside: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface inside: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface mobenga: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface escom: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface management: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface server: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface vpn: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface cafe_member: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class-default&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 08:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851096#M459625</guid>
      <dc:creator>3moloz123</dc:creator>
      <dc:date>2012-02-13T08:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: low-latency prio queue for udp traffic, but not matching ACL</title>
      <link>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851097#M459626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I started suspecting that it only matched packets for new connections (in iptables called NEW / UNREPLIED). I tested my thesis by restarting one of my openvpn tunnels, and indeed I see now a hit count of one packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question is, how come only new udp connections being matched? I would obviously like to prioritize all packets for an already established session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, the statistics after I reinitiated one of the tunnels:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa# show access-list | inc priority&lt;/P&gt;&lt;P&gt;access-list priority line 1 extended permit udp any any eq 1194 (hitcnt=1) 0xbbdd01d4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa# show service-policy&lt;/P&gt;&lt;P&gt;Global policy: &lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: QoS_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: priotraffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface outside: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface inside: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface mobenga: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface escom: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface management: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface server: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface vpn: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priority:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface cafe_member: aggregate drop 0, aggregate transmit 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class-default&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 08:46:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/low-latency-prio-queue-for-udp-traffic-but-not-matching-acl/m-p/1851097#M459626</guid>
      <dc:creator>3moloz123</dc:creator>
      <dc:date>2012-02-13T08:46:15Z</dc:date>
    </item>
  </channel>
</rss>

