QoS on ASA FOR IPSEC Tunnel

Unanswered Question
Sep 18th, 2008

class-map Pol-Lon-Tunnel

match flow ip destination-address

match tunnel-group lon-newyork

policy-map Pol-Lon-Tunnel

class Pol-Lon-Tunnel

priority

service-policy Pol-Lon-Tunnel interface outside

priority-queue outside

tx-ring-limit 128

queue-limit 2048

Guys, Not sure if the above config will work for what i am trying to do. The plan is to terminate other tunnels on this firewall and the no sysopt connection permit-vpn is enable so i am permitting the tunnel traffic using an ACL applied on the inside interface. What i need to to priotize all ipsec tunnel traffic through the firewall. I dont want any tunnel traffic dropping if the ASA output queue is fill up. Will the above config work?

Francisco

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.

Actions

This Discussion