We have a VPN gateway with around 20 tunnels to different locations around the world. Customers buy a certain bandwith from us, which often, but not always is limited by their remote internet connection.
Central internet connection is big, so no bottleneck there..
I'm looking for to provide a traffic shaping functionality to shape them to their "paid-for" bandwith.
Both for our cause, not to give anything for free, and also not to overload the remote end.
I would also like to provide a basic QoS, unfortunately it seems like CBWFQ is not supported on tunnel interfaces. RED works though...
I've done a basic configuration - what do you think of this ? :
class-map match-any tunnel
bandwidth percent 95
shape average 384000
ip address x.x.x.x
ip mtu 1420
service-policy output 384kb
tunnel source FastEthernet0/0
tunnel destination x.x.x.x
crypto map ToRemote