cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
18205
Views
115
Helpful
77
Replies

Community Ask Me Anything - Secure Remote Workers

ciscomoderator
Community Manager
Community Manager

You can ask your question on your own language:

Español  Português Français Русский  日本語 简体中文

Here’s your chance to discuss Cisco Secure Remote Working technologies such as AnyConnect, ASA, FTD, Duo, and Umbrella. In this session, the experts will answer questions about emergency licenses, design, configuration, and troubleshooting. Our experts span more than 12 time zones. Also, we’ll be translating the session into multiple languages to provide you with the best experience possible.

This forum event works well as an introduction for those who are not familiar with these security solutions and/or have recently started using them.

To participate in this event, please use the Join the Discussion : Cisco Ask the Expertbutton below to ask your questions

Ask questions from Friday, March 20 to Friday, April 3, 2020

Featured experts

divyanai.jpgDivya Nair is a Technical Marketing Engineer with the Security Business Group in Raleigh, North Carolina. She has more than 10 years of experience in Cisco network security technologies, including firewalls, IPS, VPN, and AAA; and is currently focusing on VPN and firewall management platforms. Divya holds a Bachelor's degree in Computer Science and Engineering.

 

jonnoble.jpgJonny Noble leads the Technical Marketing team for Cloud Security at Cisco, with expertise in Cisco Umbrella and surrounding technologies. For more than 20 years, Jonny has obtained experience in customer-facing disciplines for global hi-tech organizations. He also has rich experience in presenting breakout sessions and proctoring labs at Cisco Live events along with representing Cisco at numerous customer and partner events, trade shows, and exhibitions. Jonny holds degrees in Electronics, Sociology, a Business MBA, and is CISSP certified.

 

adganjoo.jpgAditya Ganjoo is a Technical Marketing Engineer in Bangalore, India. He has been working with Cisco for the past seven years in Security domains such as Firewall, VPN and AAA. Aditya has delivered trainings on ASA and VPN technologies. He holds a Bachelor's degree in Information Technology. Additionally, he is a CCIE in Security (CCIE#58938). He has been a consistent contributor on Cisco Support Community and has delivered multiple sessions at Cisco Live.

 

Due to the anticipated volume for this high in-demand event, Divya, Aditya, Jonny might not be able to answer each question. Thus, remember that you can continue the conversation directly in the Security community.

By posting a question on this event you're giving permission to be translated in all languages we have in the community.

**Helpful votes Encourage Participation! **
Please be sure to rate the Answers to Questions

77 Replies 77

Hi,

Please guide how to apply qos  for anyconnec users ?

Is it possible on ssp asa devices? 

The requirement is to give  1 Mb for each users , Remote desktop users complaining about the performance 

and also sql client users ( desktop apps  connected to sql server from remote ) .

how to  troubleshoot the sql server /database  disconnection when users are connected from remote using anyconnect 

Thanks 

 

 

Hi,

You would need to check the traffic when it gets decrypted (clear text traffic). Anyconnect would treat the SQL/DB traffic as it is doing for other traffic. You also need to ensure that the device is not overwhelmed with the VPN traffic.

Please check the ASA datasheets for more info on the throughput provided by ASA with VPN services.

Unfortunately, there is no method to throttle or rate-limit traffic per Anyconnect session on the ASA.

You can limit all AnyConnect users or remote access VPN users collectively to a certain bandwidth. Below is the sample configuration:

access-list 101 extended permit ip internal_Resource_IP internal_Resource_Mask anyconnect_IP_Pool anyconnect_Mask

class-map remote-access
match access-list 101

policy-map outside-policy
class remote-access
police output 1000000 <-- this value is 1 Mb in bits

https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/firewall/asa-98-firewall-config/conns-qos.html#ID-2133-000002dd


Please check this link for the IP config and best practices:

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/asdm78/general/asdm-78-general-config/intro-fw.html

 

For more clarity, please post the query on this forum:

 

https://community.cisco.com/t5/network-security/bd-p/discussions-network-security

Review Cisco Networking for a $25 gift card