<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QoS on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363382#M776498</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for my late response, but thanks a lot, I'm looking into it and see if it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Dec 2009 15:07:04 GMT</pubDate>
    <dc:creator>2044418Puts</dc:creator>
    <dc:date>2009-12-31T15:07:04Z</dc:date>
    <item>
      <title>QoS on ASA</title>
      <link>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363379#M776458</link>
      <description>&lt;P&gt;Hi, I would like do use Priority Queuing for voice on the OUTSIDE interface. As far as I know the QOS meganism only kicks in when there is congestion on the interface. But my ASA 5505 is connected to a 80mbps down and 10 mbps up cable modem. How can I tell the ASA that it is not connected to an interface with 100/100 mbps bandwidth?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a router I would use the bandwidth command, but this is not available on the ASA as far as I know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363379#M776458</guid>
      <dc:creator>2044418Puts</dc:creator>
      <dc:date>2019-03-11T16:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: QoS on ASA</title>
      <link>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363380#M776469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;Traffic shaping is used to match device and link speeds, thereby controlling packet loss, variable delay, and link saturation, which can cause jitter and delay. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/qos.html#wp1065649"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/qos.html#wp1065649&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example: Shaping outside interface traffic to 2 Mbps and provide priority queueing for VoIP traffic that is tagged with DSCP EF and AF13:&lt;BR /&gt; &lt;BR /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; class-map voice_traffic&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; match dscp EF AF13&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; policy-map qos_class_policy&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class voice_traffic&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; policy-map qos_outside_policy&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class class-default&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; shape average 2000000 16000&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service-policy qos_class_policy&lt;/SPAN&gt;&lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;BR style="font-weight: bold; font-family: monospace;" /&gt; &lt;SPAN style="font-weight: bold; font-family: monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; service-policy qos_outside_policy interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Dec 2009 15:24:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363380#M776469</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-27T15:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: QoS on ASA</title>
      <link>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363381#M776488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also look at that has a similar example as KS's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1230"&gt;https://supportforums.cisco.com/docs/DOC-1230#Traffic_Policing_with_Prioritization&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Dec 2009 23:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363381#M776488</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-28T23:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: QoS on ASA</title>
      <link>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363382#M776498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for my late response, but thanks a lot, I'm looking into it and see if it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Dec 2009 15:07:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363382#M776498</guid>
      <dc:creator>2044418Puts</dc:creator>
      <dc:date>2009-12-31T15:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: QoS on ASA</title>
      <link>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363383#M776524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've just tried to configure like you said, but for some reason no traffic is matching classes other than class-default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;priority-queue OUTSIDE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;service-policy OUTSIDE_PM interface OUTSIDE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;policy-map OUTSIDE_PM&lt;BR /&gt;class class-default&lt;BR /&gt;&amp;nbsp; shape average 4504000&lt;BR /&gt;&amp;nbsp; service-policy SHAPED_OUTSIDE_PM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;policy-map SHAPED_OUTSIDE_PM&lt;BR /&gt;class VOICE_CM&lt;BR /&gt;&amp;nbsp; priority&lt;BR /&gt;class LLQ_ACL_CM&lt;BR /&gt;&amp;nbsp; priority&lt;BR /&gt;class IKE_ACL_CM&lt;BR /&gt;&amp;nbsp; priority&lt;BR /&gt;class class-default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;class-map VOICE_CM&lt;BR /&gt;match dscp cs3&amp;nbsp; af31&amp;nbsp; ef &lt;BR /&gt;class-map IKE_ACL_CM&lt;BR /&gt;match access-list IKE_ACL&lt;BR /&gt;class-map LLQ_ACL_CM&lt;BR /&gt;match access-list LLQ_ACL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;access-list IKE_ACL line 1 extended permit udp any eq isakmp any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;access-list IKE_ACL line 2 extended permit udp any any eq isakmp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;access-list LLQ_ACL line 1 extended permit udp any eq 9987 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to achieve the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Shape the whole output to 4.500.000 bits / sec&lt;/LI&gt;&lt;LI&gt;Prioritize outgoing voicetraffic + voicecontrol to a priority queue within the shaper&lt;UL&gt;&lt;LI&gt;DSCP values have been verified using wireshare and the ASA capture feature.&lt;/LI&gt;&lt;LI&gt;The match statement should match regular outgoing voice, but also the outgoing voice via VPN connections. I think the last thing happens by default since according to the manual the ASA uses QOS Pre-classification by default.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Prioritize outgoing traffic according to the LLQ_ACL&lt;UL&gt;&lt;LI&gt;Inside my DMZ network i'm also running a Teamspeak server on UDP port 9987. This port has been PAT'ed through the asa from the OUTSIDE to the DMZ.&lt;/LI&gt;&lt;LI&gt;Since the packets are being send from DMZ UDP port 9987 to clients with a random high port number, I've set the ACL accordingly.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Prioritize outgoing VPN Control / IKE traffic.&lt;UL&gt;&lt;LI&gt;This one speaks for itself. There are two VPN connections running.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I let this configuration running for a while, then I did a &lt;SPAN style="font-family: courier new, courier;"&gt;"show service-policy int OUTSIDE"&lt;/SPAN&gt; and it turned out that only the class class-default had any matches:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;Interface OUTSIDE:&lt;BR /&gt;&amp;nbsp; Service-policy: OUTSIDE_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class-default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; shape (average) cir 4504000, bc 18016&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (pkts output/bytes output) 85882/21745072 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (total drops/no-buffer drops) 99/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service-policy: SHAPED_OUTSIDE_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: VOICE_CM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Queueing&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; queue limit 75 packets&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (queue depth/total drops/no-buffer drops) 0/0/0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (pkts output/bytes output) 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: LLQ_ACL_CM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Queueing&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; queue limit 75 packets&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (queue depth/total drops/no-buffer drops) 0/0/0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (pkts output/bytes output) 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: IKE_ACL_CM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Queueing&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; queue limit 75 packets&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (queue depth/total drops/no-buffer drops) 0/0/0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (pkts output/bytes output) 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class-default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Default Queueing&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; queue limit 75 packets&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (queue depth/total drops/no-buffer drops) 0/99/0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (pkts output/bytes output) 85884/21745154&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell my why this is happening and why the other classes are not being matched?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Feb 2010 14:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/qos-on-asa/m-p/1363383#M776524</guid>
      <dc:creator>2044418Puts</dc:creator>
      <dc:date>2010-02-27T14:26:34Z</dc:date>
    </item>
  </channel>
</rss>

