Improve company productivity with a Business Account.Sign Up

x
?
Solved

Shoretel Qos over Cisco ASA site to site vpn.

Posted on 2013-01-23
5
Medium Priority
?
1,367 Views
Last Modified: 2013-02-05
I have a Shoretel voip pbx. I have a remote user that connects via Site to Site vpn (Cisco ASA 5505 to Cisco ASA 5510).

How do I properly setup Qos over this link.

Thanks
0
Comment
Question by:Gary Dewrell
5 Comments
 
LVL 58

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 38813557
Here you go don't forget to change the tunnel group name to match yours ("show run tun" will tell you).

Petes-ASA(config)# class-map Voice-Traffic
Petes-ASA(config-cmap)# match dscp ef
Petes-ASA(config-cmap)# class-map Data-Traffic
Petes-ASA(config-cmap)# match tunnel-group Remote-VPN <<<Yours will be different!!
Petes-ASA(config-cmap)# match flow ip destination-address
Petes-ASA(config-cmap)# policy-map Voice-Policy
Petes-ASA(config-pmap)# class Voice-Traffic
Petes-ASA(config-pmap-c)# priority
Petes-ASA(config-pmap-c)# class Data-Traffic
Petes-ASA(config-pmap-c)# police output 200000 37500
Petes-ASA(config-pmap-c)# service-policy Voice-Policy interface outside
ERROR: Class Voice-Traffic has 'priority' set without 'priority-queue' in any interface
Petes-ASA(config)# priority-queue outside
Petes-ASA(config-priority-queue)# queue-limit 2048
Petes-ASA(config-priority-queue)# tx-ring-limit 256


Pete
0
 
LVL 15

Expert Comment

by:getzjd
ID: 38813992
Is the site to site vpn over a private backbone or over the Internet?  Given it is site to site, I am going to assume Internet.  Keep in mind that once you hit the Internet, you are at the mercy of the Internet where you are no longer control of your packets.
0
 
LVL 12

Author Comment

by:Gary Dewrell
ID: 38814234
It is over the internet.  Let me explain what I am hopeing to accomplish.

Since this is for a remote worker, I want to prioritize the viop traffic over normal data so that even if the worker is downloading a large file that his voip traffic will not suffer.  I know I can not guaranty the same accross the entire link, but if I could protect the worker from himself that would be great.

Thanks.
0
 
LVL 12

Author Comment

by:Gary Dewrell
ID: 38814246
Pete that look great but what is the:
ERROR: Class Voice-Traffic has 'priority' set without 'priority-queue' in any interface

In the middle of your example?
0

Featured Post

Get Cisco Certified in IT Security

There’s a high demand for IT security experts and network administrators who can safeguard the data that individuals, corporations, and governments rely on every day. Pursue your B.S. in Network Operations and Security and gain the credentials you need for this high-growth field.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
This article is about building a site to site VPN tunnels in Cisco CSR1000V router with IOS XE. There are two Policy Based IPsec VPN tunnels configured on CSR1000V router one with NAT and another without NAT.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

606 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question