Cisco Support Community
Community Member

How to restrict bandwidth

we have a very simple setup

L3 switch --> Pix firewall --> internet router (cisco 2801)---> ISP

We just have a default static route in L3 switch to point to pix so that all internet traffic gets routed to pix.

Now we have a bunch of users using various vpn clients to connect so that they can work in client's/partner environments. I just want that the total bandwidth consumed by such VPN traffic does not exceed 20% of total bandwidth. I want to restrict it for upload and download traffic both. I know all the destination VPN gateway IP addresses for such connections. Let me know what is best method to do it.

Community Member

Re: How to restrict bandwidth

can try class based weighted fair queuing.

For more details refer the url given below,

Re: How to restrict bandwidth


just a note: CBWFQ gives minimum bandwidth guarantees, but NO upper limit.

So the more appropriate feature to achieve your stated goals would be a shaper (or policer).

With shaping you define an upper bandwidth limit, excess traffic is queued. A policer would drop excess traffic and might not be appropriate in your case.

You could apply a shaper in each direction on your 2800. For configuration details have a look at "Policing and Shaping Overview" and consecutive chapters.

Another idea (slightly modifying your stated requirements): why not using CBWFQ and give 80% minimum guarantee to all traffic except VPN? This way you would not impose an upper limit on VPN traffic, IF no other traffic needs to be served?

Hope this helps!

Regards, Martin

Community Member

Re: How to restrict bandwidth

You could also try Policing the VPN traffic. You could match the traffic by protocol as IPSEC, or could limit the user based on IP address.

After you have matched the traffic, you will have to build a policy to police whatever traffic you are matching to either a percent of bandwidth or a fixed kbps.

Community Member

Re: How to restrict bandwidth

thanks a lot folks for your expert views. It would be great if someone can post a sample config to accompalish the shaping matching to either a percent of bandwidth or a fixed kbps.

CreatePlease to create content