Solved

Configuring QoS with a Cisco Firewall

Posted on 2010-11-08
8
1,055 Views
Last Modified: 2012-08-13
A requirement is needed to configure QoS on our Cisco Firewalls.
Have PIX/ASA Firewalls and looking to implement QoS on them.
After quite some reading, the "CiscoWorks" seems to arise quite
often as the much needed tool to help identify and configure your]
devices to manage QoS. It is not cheap.
Are there any best first steps and products I can use to help
do a proof of concept and start to configure simple QoS on my
firewalls.
Looking for other products and steps to aid QoS provisioning.
0
Comment
Question by:ccfcfc
8 Comments
 
LVL 1

Assisted Solution

by:ziaic1
ziaic1 earned 100 total points
ID: 34088793
What kind of traffic are you trying to do QoS with?  I can try to give you an example.
0
 

Assisted Solution

by:ccfcfc
ccfcfc earned 0 total points
ID: 34091041
Well we are looking at VOIP soon but want to test with traffic such as FTP, HTTP or SSL traffic.
It may be useful to test internally with traffic such as "windows copy" between networks.
We have a pending requirement to send SecureFTP (FTPS) to an external customer so would be nice to control that going out. WIll be using ACCESS LIST to control.
From what I have read CiscoWorks would let you look at your traffic and help to configure.
Appreciate any help
 
0
 
LVL 7

Accepted Solution

by:
kellemann earned 200 total points
ID: 34092321
The QoS capablities on the Pix/ASA are fairly limited, and shouldn't be the weapon of choice if you are looking for granular mechanisms to control the data.
Pix/ASA only has two queues, so you can't have a high priority for voice, a medium priority for Citrix and low for everything else. You only got high and low. Configuration is described in detail in these links:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008084de0c.shtml
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008080dfa7.shtml
0
 
LVL 5

Assisted Solution

by:Moose Mclinn
Moose Mclinn earned 200 total points
ID: 34108527
kellemann's right especially if you're doing VOIP traffic which has high packet counts, the Cisco 851's are good (and cheap) for that and have configurable ACL's and MPLS QOS
http://www.cisco.com/en/US/prod/collateral/routers/ps5853/prod_bulletin0900aecd802d0c05_ps5854_Products_Bulletin.html
IOS 12.3 and higher.

 You most likely want to do this on the switch level as well.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 

Author Comment

by:ccfcfc
ID: 34119719
Thanks I will start reading these links. We have PIX's and ASA in place .
0
 
LVL 7

Expert Comment

by:kellemann
ID: 34795468
Any news on this issue?
0
 

Author Comment

by:ccfcfc
ID: 35146902
This requirement has now dropped way down the list of priorities and no work will be carried out on it any time soon.

I will award some points to each responder for their suggestions.
0
 

Author Closing Comment

by:ccfcfc
ID: 35178737
I have answered B/partially to all grading questions as we are not in a position to test them.
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now