06-15-2017 02:52 PM - edited 03-12-2019 02:35 AM
We have a 20Mb internet connection. I would like to implement something on my ASA 5505 that limits users' bandwidth (only from the outside interface to the inside), but only if the overall usage is nearing 20Mb. So if there's only one person on the network, they can download giant files at whatever crazy speeds, but if there are 10 people and we're getting near the limit, it would throttle those connection down so that one download doesn't choke out other users. I'm not necessarily talking different types of traffic (i.e. voice packets vs others, etc...), because a lot of the traffic could all be just regular http, for example. I just want to ensure everyone has *some* connection at the most congested times, without limiting anyone when it's not congested. Is this possible? I've had trouble tracking down guidance on this particular setup.
Thanks!
Solved! Go to Solution.
06-20-2017 12:50 PM
Correct.
You would find it much simpler using a Cisco Meraki MX though.
https://meraki.cisco.com/products/appliances
This is the bit that most applies to your needs:
https://documentation.meraki.com/MX-Z/Firewall_and_Traffic_Shaping/Traffic_Shaping_Settings
06-18-2017 01:31 PM
You can't do this.
06-20-2017 09:14 AM
Is there any other way to possibly achieve anything like this? It seems a relatively likely thing to want to do. I know I've worked on storage devices that have a similar idea (you have a quota, but it's only enforced if the storage device starts to get too full, etc...), and this seemed an even more useful and easy application of the concept.
Ideally, it would be something along the line of people get the amount of bandwidth divided by number of connections, or something like that. Is it maybe possible to do it at the switch (stacked Catalyst 2960x), but just apply it to the connection out to the ASA? Or any other devices that might let us do something like this?
We have a lot of issues with machines bandwidth hogging and strangling other people's connections, but we also have a highly variable number of people in the office at any given time and it doesn't seem good to limit someone for no reason if the bandwidth is available.
06-20-2017 12:37 PM
Cisco IOS/IOS-XE routers (and Cisco Meraki MX security appliances) can do this, but not the ASAs. The ASA can enforce a hard policed limit on a type of traffic - but not divide it up amongst users.
06-20-2017 12:45 PM
Interesting. Okay, we have a 2921 ISR that we're actually not using at the moment. So the ASA 5505 can't do that, and the Catalyst 2960s can't do that, but presumably if we put the 2921 in between we could implement it there?
06-20-2017 12:50 PM
Correct.
You would find it much simpler using a Cisco Meraki MX though.
https://meraki.cisco.com/products/appliances
This is the bit that most applies to your needs:
https://documentation.meraki.com/MX-Z/Firewall_and_Traffic_Shaping/Traffic_Shaping_Settings
06-20-2017 12:55 PM
Thanks! I work at a charity, so for now I have to do the best with what we've received. In future, though, I'll keep this in mind if we get the chance to change equipment.
06-20-2017 12:58 PM
If you speak to your Cisco partner you may be able to get Charity pricing. There are also schemes like this one where partners can nominate charities to get free kit.
https://meraki.cisco.com/blog/terms-conditions-meraki-giving/
06-20-2017 01:01 PM
That's essentially how we got the current equipment (through a Cisco charitable program), and since we just got it recently, I'd hesitate to ask for more right away unless something wasn't working. But I'll put out some feelers. :-)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide