Dec 23rd, 2009
I am having PIX ver 8.0

I want to allocate 512kb bandwidth for inbound remote access VPN users accessing LAN network behind PIX. My PIX is acting as VPN server and users on internet.

Can someone help me guide how to configure it using modular policy framework?

Panos Kampanakis Wed, 12/23/2009 - 07:38
  • Cisco Employee, also explains it with examples.

You will need something like

ASA(config)# priority-queue outside

ASA(config-cmap)# class-map TG1-rest-class
ASA(config-cmap)# match tunnel-group tunnel-grp1
ASA(config-cmap)# match flow ip destination-address

ASA(config)# policy-map police-priority-policy
ASA(config-pmap-c)# class TG1-rest-class
ASA(config-pmap-c)# police output 512000
ASA(config-pmap-c)# service-policy police-priority-policy interface outside

I hope it helps.



