07-15-2013 04:56 AM - edited 03-07-2019 02:24 PM
Hi All,
Does ASA have the capibility to tag and add dscp field to packets ?
Also where do you suggest I should apply policing or shapping? closet to the source ?
for instance to limit all vlan traffic on asa 5505 interface inside to outside to 300kbps down/up, do you apply the policing to inside or outside interface ?
thanks
07-15-2013 01:04 PM
You can use policing to rate limit the traffic on your ASA. For your requirement it's better to apply it on the outside.
Please see this example
access-list SERVICIOS permit ip any 10.14.161.62 255.255.255.255
class-map CLASS-SERVICIOS
match access-list SERVICIOS
policy-map POLICY-SERVICIOS
class CLASS-SERVICIOS
police output 300000
service-policy POLICY-SERVICIOS interface outside
Please rate if this helps
07-16-2013 05:20 AM
thanks for this. I have applied on inside as I have three inside interfaces each having different subnet so all of them have the limitation imposed on them on the insidex ( x reperesenting the vlan) .
I have nothing on outside inerface.
what do you think the advantage of placing this on outside interface is ?
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide