应该配置 MPF 来针对某个接口的 in, out流量进行控制, 给你个例子:
内部接口入方向对HTTP流量进行限速(1M)
外部接口出方向对ICMP流量进行限速(56K)
ASA(config) # class-map HTTP
ASA(config-cmap) # match port tcp eq 80
ASA(config-cmap) # exit
ASA(config)#policy-map Inside-Policy
ASA(config-pmap)#class HTTP
ASA(config-pmap)# police input 1000000
ASA(config) # service-policy Inside-Policy interface Inside
ASA(config) # access-list ICMP permit icmp any any
ASA(config) # class-map ICMP
ASA(config-cmap) # match access-list ICMP
ASA(config-cmap) # exit
ASA(config)# policy-map Outside-Policy
ASA(config-pmap)# class ICMP
ASA(config-pmap)# police output 56000
ASA(config-pmap)# exit
ASA(config)#service-policy Outside-Policy interface Outside