Cisco Firewall :: 3560 - ASA Limit Bandwidth Per Subnet For Multiple Subnets
Sep 16, 2012
I have an ASA which is managing internet access from mutiple VLANs configured on a 3560 switch. I want to be able to limit the 100MB internet connection on the ASA on a per subnet (VLAN) basis for the multiple subnets configured on the switch..
so for example
VLAN10 - 10.0.10.0 - limit to 5MB
VLAN20 - 10.0.20.0 - limit to 10MB
VLAN30 - 10.0.30.0 - limit to 3MB
View 7 Replies
ADVERTISEMENT
Apr 9, 2013
I have the requirement to assign an asymmetric bandwith limit to each port on a switch (example: 4Mbps downlink, 1Mbps uplink). I've been searching and found the option to apply policers or srr-queue mechanism to achive this, however this only applies for one direction only as far as I know. Catalyst 2960 familiy is preferred, however if this is not possible, will possibly jump to the 3560X family.
View 3 Replies
View Related
Jul 15, 2009
I use WS-C3560G-24TS and try both ios 12.2.50.SE1 and 12.2.46.SE but problem the same. The config as following,
interface GigabitEthernet0/1
no switchport
ip address 1.1.1.2 255.255.255.0
[code].....
but I find the int g0/1 output traffic only can achieve about 500kbps then I try config below,
interface GigabitEthernet0/1
no switchport
[code]....
I find int g0/1 output traffic only can achieve about 5Mbps,but if I change "srr-queue bandwidth limit xx" command xx to 20-90,the int g0/1 can achieve normal traffic bps, for example,
interface GigabitEthernet0/1
no switchport
[code]...
the int g0/1 output can achieve 2Mbps that is correct,just only when limit set to 10%,the traffic only can achieve half of limit bandwidth.
View 5 Replies
View Related
Jan 24, 2013
configuring a switch or a router to limit the bandwidth for a specific user/IP when need it. Most of my remote offices are configured like this:
Users ------ 3560 switch ------- 2801 router -------- T1 to NOC -------- 7204 router with channelized DS3
I use Netflow Analyzer for high bandwidth usage alerts and can see the user's IP right away when someone is clogging our T1s. My goal is to be able to temporarily limit the bandwidth of the user taking over the T1. Whatever is best switch config or on the router.
View 2 Replies
View Related
Mar 26, 2013
I have an ASA5510 that is connected to outside for WAN, inside for LAN (10.22.254.0/24), and a iSCSI switch plugged into Ethernet 0/3 (10.22.244.0/24). I can ping the Eth0/3 interface (10.22.244.1) but I can't ping across that interface from WAN or LAN side.
START CONFIGURATION
ASA Version 9.1(1)
!
hostname ASA5510
[Code].....
View 7 Replies
View Related
Jun 23, 2011
NAT command on 8.4? I am trying to PAT multipule Inside subnets to an IP address. With the example I found I can only PAT one subnet. If I do it the way I have below, it will end up with the last subnet (3.3.3.0) stay in the config. What is the best way of doing it? I have about 20 inside subnets I need to PAT.
object network obj-Inside-sub1
subnet 1.1.1.0 255.255.255.0subnet 2.2.2.0 255.255.0.0subnet 3.3.3.0 255.255.0.0nat (inside,outside) dynamic 199.246.5.2
View 5 Replies
View Related
May 23, 2011
I have an existing pair of PIX 515E that has two interfaces. One connected to the public internet via my ISP and one internal.
I recently ran out of IP's and had the ISP route an additional block to public IP of my firewall. This isn't working for some reason and I'm trying to figure out why.
The "ip address outside XXX" command defines the outside address and I don't see any way to add a secondary sub net.
I tried just adding a rule to the firewall for one of the IP's in the new subnet, but I can't seem to get traffic to pass though the device.
View 1 Replies
View Related
Jan 5, 2012
I am new to Cisco products. We have currently got a Netgear FVX538 running in front of a few servers. We currently have 2 ranges of IP addresses provided to us on 2 separate subnets. We configured the netgear box with the first IP addresses of each subnet as the IP address of each of the primary and secondary LANs. This then allowed us to set the gateway addresses of servers on the network to either of those 2 addresses, depending on it's range.
This all worked fine - except for the fact that the Netgear box is incredibly flakey, so we decided to get a Cisco box.
We have gone for the SA520, which I have been trying to configure this afternoon. Unfortunately I am now having concerns as to whether it is possible to configure 2 separate subnets internally on this box in the same way we have done with the netgear box. ie - classical routing, one incoming WAN interface with multiple subnets?
View 5 Replies
View Related
Jun 11, 2013
I'm having a bit trouble to limit the bandwidth on outgoing traffic with a Cisco ASA 5505.
In my case I want to limit the bandwidth to 31mbit/s up and down on the outside interface. but with my current configuration, just the download rate gets limited to 31mbit/s when I do a tptest. and the upload is around 40/50mbit.
Here is the policy configuration,
access-list outside_bw extended permit ip any any
class-map outside_bw
match access-list outside_bw
[Code].....
View 1 Replies
View Related
Jul 29, 2012
In ASA 5510. How I can limit the users in (VLAN 20) to use the internet with a limited Bandwidth/speed with 3 mbps upload and 5 mbps download?
In case the outside interface (Native vlan) which is connected to the ISP and have a bandwidth/speed of 30 mbps upload and 50 mbps download.
View 4 Replies
View Related
May 22, 2013
We have an ASA 5525 running version 8.6(1)2 and a 10 MG pipe. I have execs that want to limit bandwidth on users for stuff like youtube, stream media, and downloads. I found the article on ‘Bandwidth Management(Rate Limit) Using QoS Policies’ so it appears our firewall can do what we want. I’m not a cisco person. My knowledge is limited when it comes to configuration – that’s why we have SmartNet.
Can bandwidth be limited on end users and/or can they limit the ‘bandwidth rate limit’ to just youtube, steaming media, and downloads? If so, what should the limit be? and I’m assume this would be for ‘incoming’ traffic only? we’re running into some bandwidth hogs – usually youtube and/or streaming media. We have a Barracuda web filter which we’ve used to block and monitor activity but I simply do not have time to babysit this all day. I should also mention we do have critical data running up and down the pipe; such as credit card processing, DB replication between in house DB and hosted website, TPCx and EDI, FTP, and such that we don’t want restricted.
View 7 Replies
View Related
Aug 6, 2011
I have two locations both about 800meters apart, one is my home and the other address is a campsite where i have a linked router network (WDS with routers running ddwrt) where campers can all use the internet and also i have several IP cameras. Obviously both address have different gateways and therefore their own DHCP server. Everything was running perfectly until.I linked both of my address up using a long range antenna and now i am having problems.
Sometimes the two DHCP servers are competing with each other (i need both addresses on the same subnet in order to view my IP cams from home) and sometimes the computers log on to the wrong gateway. Its very annoying because the only way i can resolve it is by turning of the "linking routers" for a minute and then the Computers log onto the correct gateway. This happens to clients both side of the bridge. I have many different clients on both side of the bridge so assigning each computer (via windows) its fixed default gateway and DNS is out of the question as some of the clients are Camper's PC's and mine and my wifes laptops swap between both locations.
Now my query is, how can i block both DCHP servers from going over the bridge? OR can i have them on both separate subnets and still view my IP camera and still access all the routers from each subnet (i need this because sometimes i need to reboot the routers from home)
View 12 Replies
View Related
Oct 28, 2012
I am planning to buy a router for my hotel and I would like to know is it possible to limit the bandwidth limit to the guests? And the admin computer can utilize the maximum speed? it it possible to create a login page paper when some one enters my wifi connection?
View 7 Replies
View Related
Aug 15, 2012
I need to NAT some subnets to one IP and other subnets to another IP. The range command want work because some of the subnets are out of order.For example subnets 192.168.1.0 - 192.168.7.0 and 192.168.25.0, 192.168.28.0 nat'd to 1.1.1.1. subnet 192.168.26.0-192.168.27.0 nat'd to 1.1.1.2
View 2 Replies
View Related
Mar 2, 2012
I've currently got my ASA (5505) serving a /28 public subnet. I've ran out of IPs, so my DC has issued me an additional /24 subnet that they have routed to my ASA. What needs to be done on my ASA so be able to use these new addresses? I've been trying to search and not been able to find a good answer (some say I shouldn't have to do anything, everything else references NATing, which I currently don't do and would rather not do).The servers I assign these to, I'd like them to have the public ip assigned directly to them.
View 5 Replies
View Related
May 2, 2012
I am a Network admin of 200 Computers.Most of our users used to download movies through torrents.I just want to now how can i limit the bandwidth for specific user for both domain and work group user
View 4 Replies
View Related
May 11, 2012
Is there a way to limit a whole PC windows XP, or a certain program to use only a certain about of your total internet connection bandwidth?For example, I have 5 PCs in home all one the same ISP connection. I have one PC that I am trying to backup files online but I can only run it at certain times due to the backup program using ALL upload/download speed. And that makes every other PC super slow.
View 3 Replies
View Related
Dec 2, 2011
If a person downloads via ADSL2 5 GB how much bandwith would this require?
View 1 Replies
View Related
Aug 26, 2011
I am setting up my home lab to practice and play around.I have VMWARE ESXi environment with two workstations as my servers.I would like to setup two domains with two domain controllers but i want each domain to have its own subnet.So this is my setup. I have Cable modem from cablevision , thay connects to my router which is Apple Airport which acts as the DHCP server. DNS server and default gateway. The network on the router is 10.0.1.xThen i have two switches . One is a 5 port unmanaged switch that connects to the three physical desktops .Then i have a Cisco small business switch SG200-08 that connects to my ESX servers and NAS. Now currently all is good and working but like i said all my machines physical or virtual get an IP that is 10.0.1.x and they get all this from the router. And i think i can setup two domains with two domain controllers without an issue and they will all get an IP address of 10.0.1.x. This is all good but i want to have one domain on one subnet and other on another so for example one domain will have 10.0.1.x and other 10.0.2.x. I am just not sure what i need to to get this setup like this. I know my SG200-08 supports vlans and i am pretty sure on the apple router you can only have one subnet i think. So can i do this with my current setup by setting up a DHCP server with two scopes ?
View 3 Replies
View Related
Jan 22, 2013
Here's what I want to do with my RV042: I have a bunch of devices, including a server, inside my network at 192.168.1.100
I've set up VPN using PPTP. It works, but if my clients have their own remote DHCP set up to 192.168.1.x, they can't get to the server. If their home DHCP is 10.x.x.x., everything works
I am considering changing my internal network to something obscure.
My server has two NICs. So I thought, I why not set one address up to 10.x.x.x But the two nets can't ping each other. I tried using "multiple subnet" on the RV042, setting up 10.1.1.1, but no luck.
View 1 Replies
View Related
Jan 24, 2013
I have a Windows 7 Pro Desktop with an on-board Ethernet and an Axis USB To Ethernet adapter. The on board Ethernet is configured as dhcp and obtain the address 10.162.146.123 with 255.255.255.0 subnet. The Axis USB to Ethernet adapter is static ip configuration with 10.38.25.37 and 255.0.0.0 as subnet. Under the adv settings I have also another ip 11.38.25.37 with 255.0.0.0 subnet. When the Axis is communicating 10.38.0.1 network I can not access the internet using the on board Ethernet 10.162.146.123. I have to disable either one of the cards to access one network at a time.
View 3 Replies
View Related
Aug 18, 2011
I am using ASA 5505 cisco firewall as a transparent firewall. I have assigned ethernet 0/0 as outside interface and ethernet0/1-7 as inside interface. There are 3 departments in office. So, i connected ethernet 0/1 to Dept A, ethernet 0/2 to Dept B and ethernet 0/3 to Dept C. Now, I want to limit bandwidth to each department, e.g, 1 Mbps download/upload to Dept A, 512 kbps download/upload to Dept B and 512 kbps download/upload to Dept C. So, how can i do this in ASA 5505.?
View 1 Replies
View Related
Feb 25, 2012
If two (one 6509A 9/26 with server A located in A end, 6509B with serverB located in B End) which is connected via a 1G link. If there is serverA send 700M file to server B via a 1G link. If I configured below command to 6509A 9/26, can I limit the bandwidth of server on bothincoming and outgoing to 500M?
class-map match-all FROM-SERVERmatch access-group name FROM-SERVER!policy-map FROM-SERVERclass FROM-SERVERpolice 500000000 conform-action transmit exceed-action drop!interface GigabitEthernet9/26service-policy in FROM-SERVER
View 1 Replies
View Related
Feb 6, 2012
I have a 3845 Router with three connected interfaces, one to my WAN, one to my LAN and another to my wifi zone. I want to limit the amount of WAN bandwidth the WIFI zone can take to say a max of one third and not restrict WAN bandwidth from the LAN at all.
View 7 Replies
View Related
Apr 29, 2012
I have cisco 7600 core router in ISP , i want to put the bandwidth limit on it for outgoing traffic (for internet) on a subnet because i am using Bluecoat and i want to test my bluecoat.On this subnet i have no limit for bluecoat but after the bluecoat i want to limit it. On 7600 cisco router i have not rate limit command so how it can be possible for a perticular subnet ?
View 1 Replies
View Related
Feb 10, 2012
I have two vlan interfaces, how to limit bandwidth on them ?I need than speed on each will be direrent.
View 1 Replies
View Related
Nov 12, 2012
VLAN ===> FE 0/1 {With subinterfaces - ALL INSIDE LAN INTERFACES} ==> ROUTER ===> BVI 0/1 {WAN Interface - OUTSIDE}
i am doing NAT for my clients in LAN to WAN - Static NAT i want one of my client who is excessing some service with his Public IP to get a specific amount of bandwidth ... as right now he is hogging all the bandwidth .i have 1841 router.
View 7 Replies
View Related
Dec 31, 2011
I want to switch to a slower ISP because of financial constraints (specifically downgrade from cable to DSL), so I'd like to set up my Windows XP computer so that it downloads and uploads at the same speed that the slower ISP does. That way I can kind of "try before I buy" for a week or so, to get an idea if I can live with the slower speed before disconnecting from cable and incurring a disconnect charge. I was told that some software that limits your bandwidth also may cause distortion in video or audio streams, so I'd like to avoid that.
View 2 Replies
View Related
May 1, 2011
My router is a GT704-WG running on the default firmware. I need to limit a certain computer's bandwidth. Am I able to set the maximum download/upload speed for a certain computer via the router control panel (192.168.1.1)?
View 11 Replies
View Related
Apr 1, 2012
On my home network I have 11 devices connected.Is there a way I can give each device a certain bandwidth limit so my Internet doesn't keep getting sucked up?
View 5 Replies
View Related
Nov 7, 2012
i have a internet cafe. i need to limit the bandwidth of our 30 computers for our customers satisfaction.
View 7 Replies
View Related
Aug 5, 2011
We have 4 RV 042 routers and cisco router at HQ, we have Site to Site VPN tunnels in between, All branch offices are connected to HQ via S2S VPN tunnels
10.10.1.0/ 24 HQ
10.10.2.0/24 Branch 1
10.10.3.0/24 Branch 2
10.10.4.0/24 Branch 3
10.10.5.0/24 Branch 4
now lets say i am branch 1, i can access 10.10.1.0/24 network but cant access 10.10.5.0/24 network, means i dont have branch to branch connection, it should be through HQ, means my RV042 at brnach should fwd all traffic to HQ for another branches also. Under VPN tunnel if i try to configure remote destination 10.10.0.0/21 its not allowing me it says network overlaping with local network, how i can sole it, I know how to do in cisco, we can permit those networks in access lists.
View 1 Replies
View Related
Feb 20, 2012
Is it possible to have multiple public IP addresses that are from different subnets going through one router? I have been told that this is not possible with most routers and that I would have to spend a lot of money on a router to be able to do it. I am still not totally clear on what defines a subnet even after reading up on them. What I am trying to achieve:
-My office has 10 computers.
-All would be connected to one router.
-My internet service provider has provided me with 10 public IP addresses, that are all very varied (which I asked for)
View 3 Replies
View Related