cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
526
Views
0
Helpful
2
Replies

ASA VPN QOS

dragec
Level 1
Level 1

Between client and server I have WAN link and on that WAN link I have QOS seted up with several trafic classes and so. If I build IPSEC VPN tunnel between client and ASA device in front of server, I guess I will lose capability to to see traffic on WAN link and my QOS will stop working.

2 Replies 2

mheusinger
Level 10
Level 10

Hi,

the IPSec standard mandates, that the TOS byte of the original header is copied into the new IPSec header. After encryption the original IP packet can not be detected by an intermediate router. Thus your QoS policy can only work, if you mark different traffic classes with f.e. different DSCP values and match on those DSCP values on your WAN router.

Hope this helps!

Regards, Martin

and where to mark packets? On client? before encryption I guess

thanks!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: