12-4
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 12 Quality of Service
Configure QoS
Additional Guidelines and Limitations
•
QoS is applied unidirectionally; only traffic that enters (or exits, depending on the QoS feature) the
interface to which you apply the policy map is affected. See
Feature Directionality, page 1-4
for
more information.
•
For priority traffic, you cannot use the
class-default
class map.
•
For priority queuing, the priority queue must be configured for a physical interface or, for the
ASASM, a VLAN.
•
For policing, to-the-box traffic is not supported.
•
For policing, traffic to and from a VPN tunnel bypasses interface policing.
•
For policing, when you match a tunnel group class map, only outbound policing is supported.
Configure QoS
Use the following sequence to implement QoS on the ASA.
Step 1
Determine the Queue and TX Ring Limits for a Priority Queue, page 12-4
Step 2
Configure the Priority Queue for an Interface, page 12-6
.
Step 3
Configure a Service Rule for Priority Queuing and Policing, page 12-7
.
Determine the Queue and TX Ring Limits for a Priority Queue
Use the following worksheets to determine the priority queue and TX ring limits.
•
Queue Limit Worksheet, page 12-4
•
TX Ring Limit Worksheet, page 12-5
Queue Limit Worksheet
The following worksheet shows how to calculate the priority queue size. Because queues are not of
infinite size, they can fill and overflow. When a queue is full, any additional packets cannot get into the
queue and are dropped (called
tail drop
). To avoid having the queue fill up, you can adjust the queue
buffer size according to
Configure the Priority Queue for an Interface, page 12-6
Tips on the worksheet:
•
Outbound bandwidth—For example, DSL might have an uplink speed of 768 Kbps. Check with your
provider.
•
Average packet size—Determine this value from a codec or sampling size. For example, for VoIP
over VPN, you might use 160 bytes. We recommend 256 bytes if you do not know what size to use.
•
Delay—The delay depends on your application. For example, the recommended maximum delay for
VoIP is 200 ms. We recommend 500 ms if you do not know what delay to use.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...