In our example below, we present a usual scenario in which we have two (or more)
sites communicating through a Lan-to-Lan IPSEC VPN via the Internet.
Between the sites we can have both data and VoIP traffic communication.
Although we can not enforce real QoS through the Internet, at least we can ensure
voice traffic prioritization on the firewall interface.

From the diagram above we assume that we have already configured the IPSEC VPN
and is working properly (i.e both subnets 192.168.1.0/24 and 192.168.2.0/24 can
communicate via the tunnel).
The example configuration below is for the ASA-1 firewall and should be applied accordingly
to ASA-2 for better QoS performance.
!
Enable a priority queue on the outside interface
ASA-1(config)# priority-queue outside
ASA-1(config-priority-queue)# exit
!
Select VoIP traffic for prioritization
access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq h323
!
access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq sip
!
access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq 2000
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq h323
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq sip
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq 2000
!
Match the ACL and traffic with Expedited Forwarding (EF)
class-map Voice-OUT
match dscp ef
match access-list VoIP-Traffic-OUT
exit
!
class-map Voice-IN
match dscp ef
match access-list VoIP-Traffic-IN
exit
!
Configure the actual policy that will be applied to the interface
policy-map VoicePolicy
class Voice-OUT
priority
exit
class Voice-IN
priority
exit
!
Apply the policy to the outside interface
service-policy VoicePolicy interface outside
In your example above. Please indicate ASA-2 outside interface with a priority queue
applied to it’s outside interface matching traffic going from 192.168.2.0/24 to 192.168.1.0/24.