Solved

Traffic shaping in Cisco 3745 router

Posted on 2007-11-17
7
853 Views
Last Modified: 2009-11-25
Here is our internet setup

we are getting of 1 MB from which is connected as follows
                         ISP      
                         |
                        |
                        |
                         |
                        |
                        |
                       ROUTER (212.x.x.145)Cisco 3745 IOS ver 12.3(17b)
                         |
                        |
                        |Cisco 3550
            (212.x.x.147)  SWITCH--------- MANAGEMENT (212.x.x.149)
                         |
                        |
                        |
                       Firewall(212.x.x.146) - PIX 525 (7.0.6)
                         |     |
             10.0.0.3      |     |172.16.31.1
                         |     |
                         |     |
                        LAN    DMZ SWITCH Cisco 3550
                        |      |    |    |
                        |      |    |    |
                        |      |    |    |
                        |      |    |    |
                    NAT & PAT  ISA   WEB  EXCH    

We have done following things
NAT 10.0.0.6 to 212.x.x.157,
PAT 10.0.0.0/20 to 212.x.x.157
ISA, WEB, EXCH server is DMZ zone
Following are the details of NAT

SERVR      INETRNAL IP   DMZ IP        NATTED IP
ISA       10.0.1.108 -  172.16.31.3  212.x.x.151
WEB     10.0.1.109    172.16.31.4  212.x.x.150
EXCH    10.0.1.30     172.16.31.5  212.x.x.148

Now I am planning to create a time based access-list from 7 AM to 8 PM

I want to assign following bandwidth

ISA Server 800 K
MANAGEMENT 50 K
NAT        50 K
PAT        50 K
WEB        100 K
EXCH       200 K

I am trying this by access-list but it seems not working is there any way are if thro access-list then how should I do. Also for the ISA server i just need to close all the ports except http, https. gre for VPN, MSN & YAHOO messenger. FOr web server and MANAGEMENT I need just Http, https, and FTP. For EXCH I need pop3, smtps and https.

I am using following access-list in my router for the traffic shaping

access-list 101 permit 212.x.x.151
access-list 102 permit 212.x.x.148
access-list 103 permit 212.x.x.150
!
interface fastethernet 0/0
 traffic-shape group 101 800000
 traffic-shape group 102 200000
 traffic-shape group 103 100000

Cheers
Khaleej
0
Comment
Question by:alkhaleej
  • 3
  • 2
7 Comments
 
LVL 11

Accepted Solution

by:
tvman_od earned 500 total points
ID: 20305913
1. Traffic shaping works in OUTGOING direction only.
2. I would use class based queueing which would allow to assign minimum bandwidth for each class and let it take more when there is no traffic of other classes.
0
 

Author Comment

by:alkhaleej
ID: 20306549
then  how should I implement the class based queuing any documents
0
 
LVL 11

Assisted Solution

by:tvman_od
tvman_od earned 500 total points
ID: 20308102
For basic conceptions I'd start here
http://www.cisco.com/univercd/cc/td/doc/cisintwk/ito_doc/qos.htm
Here is some white papers
http://www.cisco.com/en/US/products/ps6613/prod_white_papers_list.html

For specific configuration samples just google by kywords from the documents or ask me, feel free to keep this question opened.
0
 

Author Comment

by:alkhaleej
ID: 20310826
Well it would be better you post a sample configuration based on my setup
0
 
LVL 11

Assisted Solution

by:tvman_od
tvman_od earned 500 total points
ID: 20315152
I prefer to give people ideas how to slolve the problem but samples which would be questioned over and over again. If you understand why it's done this way, you can modify it to fit your needs next time.
Did you read articles which I gave you? Could you point on subjects which you need to be explained in simple words?

Typical config for outgoing QoS policy would be:

access-list extended default
 permit ip any any  

class-map match-any EF
match ip precedence 5  
match ip dscp ef  

class-map match-any AF41
   match protocol ssh
   match protocol rcmd
   match protocol telnet
   match access-group name <your app>
   
class-map match-any AF31
  match protocol dns
  match protocol notes
  match protocol xwindows
  match protocol citrix
  match access-group name <your app>

class-map match-any AF21
    match ip dscp AF21

class-map match-any BE
  match access-group default


policy-map QoS
 class EF
   set ip dscp ef
    priority 512  
class AF41
   set ip dscp af41
   bandwidth ...  
class AF31
   bandwidth ...  
   set ip dscp af31
class AF21
   bandwidth ...  
   set ip dscp af21
 class BE
   bandwidth ...  
   set ip dscp default  


interface Serial0
 bandwidth 1536
 no ip address
 encapsulation frame-relay IETF
 no fair-queue
service-policy output QoS  
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

In a WLAN, anything you broadcast over the air can be intercepted.  By default a wireless network is wide open to all until security is configured. Even when security is configured information can still be intercepted! It is very important that you …
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now