cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
568
Views
0
Helpful
4
Replies

QoS for tunnels

Priyank Ghedia
Level 1
Level 1

Scenario: My client has multiple sites that connect to a single POP via IPSEC tunnels over the internet. Each site has two tunnels to the POP, one for internet traffic and other for production traffic. The internet traffic breaks out from the FW at the POP and the production traffic rides the MPLS. Both the CE and PE devices are Cisco. CE devices are Cisco 1921-SEC/K9 or higher. PE device is Cisco 3925-SEC/K9.

Question: The client wants us to implement Queing for both types of traffic. It is easy to do so at the CE side as the 2 tunnels originate from a single interface and BW shaping can be implemented using Parent-Child MQC for each of the 2 tunnels. The idea here is not to dedicate or 'Police' the BW per tunnel. Rather if one tunnel is not using the assigned BW then the other tunnel should be able to use the available BW. The problem I am facing is on the PE side where multiple tunnels will terminate on a single public facing interface. I want to apply similar QoS policy on PE for CE bound traffic (return traffic), where the BW is shared by the 2 tunnels/site.

Your input will be very much appreciated.

4 Replies 4

Joseph W. Doherty
Hall of Fame
Hall of Fame

Bottleneck is PE<>CE link?  You'll be able to set QoS on PE side to CE side (for inbound traffic)?

Yes the bottleneck is PE to CE bound traffic. I am able to set QoS on PE side for outbound traffic towards the CE.

Ok, then it's unclear to me what's the problem.  Why can't you configure QoS on the PE to CE interface?

Yes I can configure QoS on the PE to CE bound interface but I am want to implement 3 levels of hierarchy. 1st at the interface level for BW shaping. 2nd at the tunnel level where I am shaping the BW for a pair of tunnels and 3rd at each tunnel level where I am implementing a queing related policy. I am skpeptical that this is possible, but I am looking for a way to implement this design. I have attached a image of what I am trying to do, let me know if that makes sense.

Review Cisco Networking products for a $25 gift card