Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi all,
please for your valuable help in making some things clear for me regarding QoS rate-limiting and traffic shaping. Please share your feedback and any suggestions for the following scenario.
Consider the below topology:
Let's say User A (19...
Hi all, please for your help on the below.
I am trying to rate-limit a couple of internal subnets for traffic to the Internet, to keep them from overwhelming our Internet feed (50Mbps) but the limit does not work. I have set a maximum input/ouput p...
Hi all, I am trying to setup a VTI based IPSec VPN in GNS3 using IOS c7200-adventerprisek9-mz.152-4.S7The topology is attached. Tunnel is between R1 and R3. The tunnel comes up and IKE and IPSEC SAs are build. From R1 I can ping 192.168.2.1 using sou...
We have the USERS subnet at 192.168.110.0/23. The 192.168.110.6 is a user that has "elevated" Internet privileges as opposed to the other "normal" users, and he creates so much download traffic that he bottlenecks the whole network (he is constantly ...
Priority queuing is enabled only on the OUTSIDE interface. Still I am not sure that priority-queuing has anything to do with rate-liming actions, I think setting a priority queue is only necessary if you want to prioritize some traffic like for examp...
I am refreshing the post in case someone could offer some help on this issue.
In short when setting up an IPSec VPN using SVTIs, the tunnel comes up and pings from routers are possible but nothing sourced from LAN hosts works. Traffic sourced from ...
Hi, below is the output of debug crypto isakmp: R2(config-if)#tunnel protection ipsec profile IKEV1-PROFILER2(config-if)#*Sep 29 09:41:45.483: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON*Sep 29 09:41:45.507: ISAKMP:(0): SA request profile is (NULL)*Sep 29 ...
If I set "tunnel mode gre ip" pings start working between all hosts on the two LANs. But encryption is not used, no encrypted packet is ever being send across and no IKE nor IPSEC SAs are buing build, so communication is unencrypted Thanks for the in...