08-26-2019 04:05 AM
Hello everybody!
I am a (very) begginer needing some help.
I have a network divided in several vlans managed by an ISR 891F. The 891 is the dhcp server for each vlan.
One of the vlan (let's name it FREE WIFI VLAN - 10.10.21.0/24) includes all the AccessPoints in the building providing free wifi to the clients. (APs are not Cisco). All the APs are connected in the same (2960X-24ts-l) switch.
Can you tell me how can I limit the traffic (both ingress and egress) only for this vlan (ISP provides a guaranteed upload/download speed) in order to leave the other vlans to access the internet with priority and better speed?
Thank you!
08-26-2019 05:55 AM
Hello MichaelCM,
if you know the IP subnet used by free WIFI you can build QoS policies to limit their traffic usage.
>> FREE WIFI VLAN - 10.10.21.0/24
access-list 111 remark FREE WIFI to internet
access-list 111 permit ip 10.10.21.0 0.0.0.255 any
access-list 121 remark from internet to FREE WIFI
access-list 121 permit ip any 10.10.21.0 0.0.0.255
class-map FREEWIFI-UPSTREAM
match address 111
class-map DOWNSTREAM-FREEWIFI
match address 121
policy-map POLICER-to-INTERNET
class FREEWIFI-UPSTREAM
police 5000000 conform-action transmit exceed-action-drop
!
policy CHILD
class DOWNSTREAM-FREEWIFI
shape average 10000000
policy-map SHAPE-from-Internet
class-default shape 100000000
service-policy CHILD
interface gi0/0
desc link router to switch
service-policy in POLICER-to-INTERNET
service-policy out SHAPE-from-Internet
Of course, you need also to NAT the WIFI users to give them internet access
Hope to help
Giuseppe
08-28-2019 12:56 AM
Thank you, very much! Will try it!
08-26-2019 08:31 AM
08-28-2019 12:55 AM
Thank you!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide