Networking-Blog

My WordPress Blog

CISCO – ASA HTTP QOS Traffic

priority-queue outside
exit
!
access-list
Http-Traffic-OUT extended permit tcp
172.16.0.0 255.255.0.0 any eq http
!

class-map http_traffic
match dscp ef
match access-list Http-Traffic-OUT
!
policy-map
http_traffic_policy
class http_traffic
inspect http
police output 750000
!

service-policy http_traffic_policy interface outside

Cisco ASA QoS for VoIP Traffic

In our example below, we present a usual scenario in which we have two (or more)
sites communicating through a Lan-to-Lan IPSEC VPN via the Internet.

Between the sites we can have both data and VoIP traffic communication.
Although we can not enforce real QoS through the Internet, at least we can ensure
voice traffic prioritization on the firewall interface.

From the diagram above we assume that we have already configured the IPSEC VPN
and is working properly (i.e both subnets 192.168.1.0/24 and 192.168.2.0/24 can
communicate via the tunnel
).

The example configuration below is for the ASA-1 firewall and should be applied accordingly
to ASA-2 for better QoS performance.

!

Enable a priority queue on the outside interface

ASA-1(config)# priority-queue outside
ASA-1(config-priority-queue)# exit

!

Select VoIP traffic for prioritization

access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq h323
!
access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq sip
!
access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq 2000
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq h323
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq sip
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq 2000
!

Match the ACL and traffic with Expedited Forwarding (EF)

class-map Voice-OUT
match dscp ef
match access-list VoIP-Traffic-OUT
exit
!
class-map Voice-IN
match dscp ef
match access-list VoIP-Traffic-IN
exit

!

Configure the actual policy that will be applied to the interface

policy-map VoicePolicy
class Voice-OUT
priority
exit

class Voice-IN
priority
exit

!

Apply the policy to the outside interface

service-policy VoicePolicy interface outside

In your example above. Please indicate ASA-2 outside interface with a priority queue
applied to it’s outside interface matching traffic going from 192.168.2.0/24 to 192.168.1.0/24.