<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Per flow policing that is not into a VPN. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/per-flow-policing-that-is-not-into-a-vpn/m-p/1226372#M860775</link>
    <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the ASA police flows based on the destination IP but not related to a VPN tunnel?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to set download rate limits to my users.  Limit each individual IP to 2megs on Internet to help smooth out the peaks in the Intnernet pipe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking that i want to match on destination IP in the direction of transmitting out the inside interface.  This should give me a per IP flow policing policy but the ASA wants the 'match tunnel group' statement first so it seems the per flow policing feature is only usable within a tunnel?  Do&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:19:42 GMT</pubDate>
    <dc:creator>jcosgrove</dc:creator>
    <dc:date>2019-03-11T15:19:42Z</dc:date>
    <item>
      <title>Per flow policing that is not into a VPN.</title>
      <link>https://community.cisco.com/t5/network-security/per-flow-policing-that-is-not-into-a-vpn/m-p/1226372#M860775</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the ASA police flows based on the destination IP but not related to a VPN tunnel?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to set download rate limits to my users.  Limit each individual IP to 2megs on Internet to help smooth out the peaks in the Intnernet pipe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking that i want to match on destination IP in the direction of transmitting out the inside interface.  This should give me a per IP flow policing policy but the ASA wants the 'match tunnel group' statement first so it seems the per flow policing feature is only usable within a tunnel?  Do&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/per-flow-policing-that-is-not-into-a-vpn/m-p/1226372#M860775</guid>
      <dc:creator>jcosgrove</dc:creator>
      <dc:date>2019-03-11T15:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Per flow policing that is not into a VPN.</title>
      <link>https://community.cisco.com/t5/network-security/per-flow-policing-that-is-not-into-a-vpn/m-p/1226373#M860776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 extended permit ip any 192.168.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map police_class&lt;/P&gt;&lt;P&gt; match access-list 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map police_policy&lt;/P&gt;&lt;P&gt; class police_class&lt;/P&gt;&lt;P&gt;  police input 2000000 &lt;/P&gt;&lt;P&gt;  police output 2000000 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 04:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/per-flow-policing-that-is-not-into-a-vpn/m-p/1226373#M860776</guid>
      <dc:creator>roshan.maskey</dc:creator>
      <dc:date>2009-04-17T04:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Per flow policing that is not into a VPN.</title>
      <link>https://community.cisco.com/t5/network-security/per-flow-policing-that-is-not-into-a-vpn/m-p/1226374#M860777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your response.  This is about how far I have gotten it but I think this will police the entire class,  in this case the 192.168.10.0/24 network.  So the sum of all traffic on this network would be 2 meg as in your example and not per user.  Am I wrong about this?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 09:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/per-flow-policing-that-is-not-into-a-vpn/m-p/1226374#M860777</guid>
      <dc:creator>jcosgrove</dc:creator>
      <dc:date>2009-04-17T09:51:23Z</dc:date>
    </item>
  </channel>
</rss>

