<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA // shaping vs. policing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-shaping-vs-policing/m-p/1175214#M860513</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you can configure "service-policy (class)" coomand on ASA for traffic shaping. Hierarchical priority queueing is used on interfaces on which you enable a traffic shaping queue. A subset of the shaped traffic can be prioritized. The standard priority queue is not used (the priority-queue command). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1301526" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1301526&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Apr 2009 18:58:39 GMT</pubDate>
    <dc:creator />
    <dc:date>2009-04-30T18:58:39Z</dc:date>
    <item>
      <title>ASA // shaping vs. policing</title>
      <link>https://community.cisco.com/t5/network-security/asa-shaping-vs-policing/m-p/1175213#M860509</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to apply individual shaping for different classes of traffic which are traversing an ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The documentation of ASA (8.0) tells me that "Traffic shaping must be applied to all outgoing traffic on a physical interface or in the case of the ASA 5505, on a VLAN. You cannot configure traffic shaping for specific types of traffic."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So that means I can't divide the traffic into smaller subsets (for instance, IP-subnets) and shape them individually. I could do policing instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I see here is that I have had bad experiences with policing in regards with performance of TCP-sessions. It's no surprise: If there is a threshhold over which every packet is just dropped, it triggers TCP to drop down and after a while to "build up" the used bandwidth, resulting in a sawtooth-pattern in used bandwidth. Shaping is much better in this regards, as it smoothens the used bandwidth perfectly to the set threshhold.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could imagine that this problem is neglectible if there is a number of clients large enough falling into one class, as the problem distributes over more clients, but this is not always the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody please give some input here on how to tackle this problem, e.g. how to make policing work better or alternative solutions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Florian&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:23:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-shaping-vs-policing/m-p/1175213#M860509</guid>
      <dc:creator>Florian Pressler</dc:creator>
      <dc:date>2019-03-11T15:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA // shaping vs. policing</title>
      <link>https://community.cisco.com/t5/network-security/asa-shaping-vs-policing/m-p/1175214#M860513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you can configure "service-policy (class)" coomand on ASA for traffic shaping. Hierarchical priority queueing is used on interfaces on which you enable a traffic shaping queue. A subset of the shaped traffic can be prioritized. The standard priority queue is not used (the priority-queue command). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1301526" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1301526&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2009 18:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-shaping-vs-policing/m-p/1175214#M860513</guid>
      <dc:creator />
      <dc:date>2009-04-30T18:58:39Z</dc:date>
    </item>
  </channel>
</rss>

