Pre-Classify QoS and IPSec

Answered Question
Apr 6th, 2010

Trying to create pre-classify QoS policy that will give a certain network traffic/subnet priority over other interesting traffic crypto ACLs... something like this;

crypto ACLs:

access-list 101 permit ip 128.0.0.0 127.255.255.255 host 1.1.1.1

access-list 101 permit ip 128.0.0.0 127.255.255.255 host 2.2.2.2

traffic/ACL that needs to have priority:

access-list 102 permit ip 128.0.0.0 127.255.255.255 host 2.2.2.2

the interesting traffic "101" crypto ACLs will be assign to the crypto map policy.

the priority 102 ACL will be assign to a class map, then to a policy-map?

class-map match-any voip-vlan

match access-group 102

policy-map voip

class voip-vlan

  bandwidth 200

  police cir 5000000

will this work, or am i missing something?

thanks, kevin

I have this problem too.
0 votes
Correct Answer by Federico Coto F... about 6 years 9 months ago

Hi,

The policy-map should be assigned to the global service-policy or to an interface service-policy.

Federico.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Federico Coto F... Tue, 04/06/2010 - 07:33

Hi,

The policy-map should be assigned to the global service-policy or to an interface service-policy.

Federico.

Actions

This Discussion