Hi everyone,
We're in the process of switching over our phone system from a legacy Nortel MICS and are currently playing with a FreePBX implementation. Our network consists of Cisco Catalyst 2690 switches, Dell PowerConnect 3448P PoE switches, and an ASA5510. We have no layer 3 switches or separate routers and are hoping to avoid adding either for cost reasons.
The ASA has 4 interfaces configured: inside, outside, dmz, and guest_inside. We host our own mail and web servers which sit on the DMZ. We also have a WLC-2504 which has one interface on our inside network and another connected to the guest_inside interface on the ASA.
Our internal network configuration consists of one VLAN (vlan 1). We’re currently in an experimentation phase with FreePBX and are trying to understand how to best configure QoS, separate VLANs, etc.
After that long winded intro, I have some questions:
1. We have 2 Dell PowerConnect 3448P switches set aside for use only with VoIP phones. We’re currently using the ASA as a DHCP Server on the inside interface and we’ll also need DHCP (and option 66) for the VoIP phones. What’s the best way to connect the Dell PoE switches to the network:
A. Connect them to the existing Cisco switch stack with a trunk and create a VLAN for VoIP on the Dell switch ports?
B. Create another interface on the ASA (inside_voip for example) with the same security level as the inside interface (100) and create a VLAN for VoIP on the Dell switch ports?
C. Create sub-interfaces on the inside interface and let the ASA handle intervlan routing and create a VLAN for VoIP on the Dell switch ports?
D. Something else?
2. What’s the best strategy for setting up QoS on the ASA? I’ve read the “Configuring QoS” ASDM help docs and they aren’t particularly helpful. Ultimately, I want to give absolute priority to voice and it’s not clear to me if I just need to setup a Priority Queue, Policing, Traffic Shaping, or some combination of the 3.
Thanks -- Steve
2. You'll want all three. This http://www.laguiadelnetworking.com/how-to-enable-qos-priority-queue-on-the-cisco-asa-firewall/ will help, as will this: https://albahra.com/journal/2013/04/crash-course-cisco-asa-5505-setup-with-qos