Solved

Prioritize traffic by external ip address

Posted on 2006-07-21
7
390 Views
Last Modified: 2010-04-08
Is there anyway to prioritize traffic through a PIX 515e by someones external ip address.

We have one person working from home and would like all the traffic that he is pulling out of our facility to have a higher priority than everything else.  Is this possible?


Thank you.
0
Comment
Question by:cbones
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
7 Comments
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 17159952
First you have to have PIX OS 7.x loaded, then you can configure a priority policy with an acl attached to it that matches the traffic you want to give priority
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 17159954
if you need an example I can post one
0
 

Author Comment

by:cbones
ID: 17159984
Can you please post an example of priority traffic?

Thank you very much for your help!
0
Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

 
LVL 25

Expert Comment

by:Cyclops3590
ID: 17161201
will when i get into work later today....btw, you do have version 7.x OS on your firewall right?   if not, you don't have the ability to configure priority.  and even though you can upgrade to 7.x on that PIX, there is a lot of changes that happened from 6.x to 7.x so you'd need to research the changes before upgrading.

but i'll be posting my example in a little bit
0
 
LVL 25

Accepted Solution

by:
Cyclops3590 earned 250 total points
ID: 17170383
k, sorry it took so long, here ya go

first create an acl to match the traffic you want to give priority

class-map <class name>
 match access-list <acl to match to>

policy-map <policy name>
 class <class name>
  priority

service-policy <policy name> interface outside

priority-queue outside
  queue-limit   200
  tx-ring-limit 100

this will take a little while to take effect too btw.   Also all this does is move this traffic into another queue that has priority over the default best-effort queue.  If you setup a lot of priority classes, all of them have the same priority; unlike routers which can be configured with much better priority queuing (0-7 level)
0
 

Author Comment

by:cbones
ID: 17178127
Thank you for your help.  The current pix we have does not have version 7 but a lower version 6.3...
I am looking into upgrading or purchasing a new pix with the latest software.

Thank you again for your time.
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 17178733
no problem.....keep in mind though that going from 6.3 to 7.x there are a lot of changes that happened
pptp is gone -> ipsec only
conduits are gone -> acl only
vpngroup are gone ->you now have group-policy and  tunnel-group
ip address <int> is gone -> interfaces are handled like on routers now

basically I can't stress enough to do the research.  And depending upon the complexity of your config it may just be easier to re-write it and start from scratch in 7.x
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
PFsense box as firewall 5 66
Sonicwall SOHO Firewall port access 5 94
What ports to open for KMS on an L7 Application based firewall? 1 97
firewall inside of network 9 83
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question