QoS on ASA FOR IPSEC Tunnel

Unanswered Question
Sep 18th, 2008
User Badges:
  • Gold, 750 points or more

class-map Pol-Lon-Tunnel

match flow ip destination-address

match tunnel-group lon-newyork


policy-map Pol-Lon-Tunnel

class Pol-Lon-Tunnel

priority


service-policy Pol-Lon-Tunnel interface outside


priority-queue outside

tx-ring-limit 128

queue-limit 2048


Guys, Not sure if the above config will work for what i am trying to do. The plan is to terminate other tunnels on this firewall and the no sysopt connection permit-vpn is enable so i am permitting the tunnel traffic using an ACL applied on the inside interface. What i need to to priotize all ipsec tunnel traffic through the firewall. I dont want any tunnel traffic dropping if the ASA output queue is fill up. Will the above config work?


Francisco



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.

Actions

This Discussion