Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

QoS on ASA FOR IPSEC Tunnel

class-map Pol-Lon-Tunnel

match flow ip destination-address

match tunnel-group lon-newyork

policy-map Pol-Lon-Tunnel

class Pol-Lon-Tunnel

priority

service-policy Pol-Lon-Tunnel interface outside

priority-queue outside

tx-ring-limit 128

queue-limit 2048

Guys, Not sure if the above config will work for what i am trying to do. The plan is to terminate other tunnels on this firewall and the no sysopt connection permit-vpn is enable so i am permitting the tunnel traffic using an ACL applied on the inside interface. What i need to to priotize all ipsec tunnel traffic through the firewall. I dont want any tunnel traffic dropping if the ASA output queue is fill up. Will the above config work?

Francisco

1 REPLY

Re: QoS on ASA FOR IPSEC Tunnel

what sugest u is to have a look at the following link will help u alot and u are on the right path in ur config :)

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008084de0c.shtml

good luck

if helpful Rate

1235
Views
0
Helpful
1
Replies