cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9873
Views
0
Helpful
9
Replies

Traffic shaping per users , ip ,application using ASA

acharyr123
Level 3
Level 3

Hi,

I hava Cisco ASA 5520 with AIP-SSM module. I would like to have the below features with ASA installed in Transparent mode.

1. Traffic shapping per user

2.  Traffic shapping per IP subnet

3.  Traffic shapping per Application

Is it possible with ASA installed in Transparent mode??

9 Replies 9

padatta
Level 1
Level 1

Hi,

Unfortunately traffic shaping is not supported in transparent mode.

Here is the reference.

http://www.cisco.com/en/US/partner/docs/security/asa/asa82/configuration/guide/conns_qos.html#wp1111709

Paps

Thanks for your prompt support....

Whether this feature is supported in Routed mode??

Regards,

Partha

Hello Partha,


The feature is supported in Routed mode.

Please mark the post answered for others to refer in future.

Cheers,
Chirag

Hello,

I have an ASA 5520 in routed mode and would like to shape based on IP address. Can anyone share any configuration examples for this?

Trent

Hi, See below a QoS config example for an ASA

https://supportforums.cisco.com/docs/DOC-1230

Don't forget to rate posts that are helpful.

Thanks for the link. If I apply a QoS policy, be it shaping or policing, does that affect EACH INDIVIDUAL CONNECTION (ip address) on the interface? Or does it QoS the ENTIRE interface? I am looking limit bandwitdh on a per connection/ip address basis.


Trent

Daryl,

It rate limits the connection based on ip address for traffic going from that particular interface only. It woudl not rate limit any other IP address not specified in the ACL for QoS that we have created. We specify the interface just to notify the ingress and egress point of the traffic.

Thanks,

Varun

Thanks,
Varun Rao

Just to clarify, all I would need to do is set up policing and it will be done on a per IP basis (kinda new at this ASA)? Also, can shaping be done in the ASDM or can I only police?

Trent

FOr shaping you can follow this doc:

http://www.cisco.com/en/US/partner/docs/security/asdm/6_2/user/guide/qos.html#wp1065249

Plicing would b done as per IP basis, through ACL

Thanks,

Varun

Thanks,
Varun Rao
Review Cisco Networking for a $25 gift card