Shoretel Qos over Cisco ASA site to site vpn.

Posted on 2013-01-23
Last Modified: 2013-02-05
I have a Shoretel voip pbx. I have a remote user that connects via Site to Site vpn (Cisco ASA 5505 to Cisco ASA 5510).

How do I properly setup Qos over this link.

Question by:Gary Dewrell

Expert Comment

ID: 38812363
LVL 57

Accepted Solution

Pete Long earned 500 total points
ID: 38813557
Here you go don't forget to change the tunnel group name to match yours ("show run tun" will tell you).

Petes-ASA(config)# class-map Voice-Traffic
Petes-ASA(config-cmap)# match dscp ef
Petes-ASA(config-cmap)# class-map Data-Traffic
Petes-ASA(config-cmap)# match tunnel-group Remote-VPN <<<Yours will be different!!
Petes-ASA(config-cmap)# match flow ip destination-address
Petes-ASA(config-cmap)# policy-map Voice-Policy
Petes-ASA(config-pmap)# class Voice-Traffic
Petes-ASA(config-pmap-c)# priority
Petes-ASA(config-pmap-c)# class Data-Traffic
Petes-ASA(config-pmap-c)# police output 200000 37500
Petes-ASA(config-pmap-c)# service-policy Voice-Policy interface outside
ERROR: Class Voice-Traffic has 'priority' set without 'priority-queue' in any interface
Petes-ASA(config)# priority-queue outside
Petes-ASA(config-priority-queue)# queue-limit 2048
Petes-ASA(config-priority-queue)# tx-ring-limit 256

LVL 15

Expert Comment

ID: 38813992
Is the site to site vpn over a private backbone or over the Internet?  Given it is site to site, I am going to assume Internet.  Keep in mind that once you hit the Internet, you are at the mercy of the Internet where you are no longer control of your packets.
LVL 12

Author Comment

by:Gary Dewrell
ID: 38814234
It is over the internet.  Let me explain what I am hopeing to accomplish.

Since this is for a remote worker, I want to prioritize the viop traffic over normal data so that even if the worker is downloading a large file that his voip traffic will not suffer.  I know I can not guaranty the same accross the entire link, but if I could protect the worker from himself that would be great.

LVL 12

Author Comment

by:Gary Dewrell
ID: 38814246
Pete that look great but what is the:
ERROR: Class Voice-Traffic has 'priority' set without 'priority-queue' in any interface

In the middle of your example?

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Provisioning vcpu for VM (cisco virl) 4 65
Guest Wi-Fi Time out 3 28
Cisco Router Security Commands. 2 31
AnyConnect VPN endpoint authentication/validation 4 16
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question