Creating a Policy for Traffic Shaping and Hierarchical Priority Queueing
You can create a policy map for an interface or globally for all interfaces that assigns QoS actions (and other feature actions) to the traffic in the class map. (See the Chapter 21, "Using Modular Policy Framework," for information about other features. This chapter only discusses QoS.)
You can configure traffic shaping for all traffic on an interface, and optionally hierarchical priority queueing for a subset of latency-sensitive traffic. See the "How QoS Features Interact" section on page 24-4 for information about valid QoS configurations.
If you want to configure hierarchical priority queueing, then first identify the traffic in "Identifying Traffic for QoS Using Class Maps" section on page 24-6; traffic shaping always uses the class-default class map, which is automatically available.
One side-effect of priority queueing is packet re-ordering. For IPSec packets, out-of-order packets that are not within the anti-replay window generate warning syslog messages. These warnings are false alarms in the case of priority queueing. You can configure the IPSec anti-replay window size to avoid possible false alarms. See the crypto ipsec security-association replay command in the Cisco Security Appliance Command Reference.
To create a policy map, perform the following steps:
Step 1 (Optional) For hierarchical priority queueing, create a policy map that applies the priority queueing action to a class map by entering the following commands:
hostname(config)# policy-map name hostname(config-pmap)# class priority_map_name hostname(config-pmap-c)# priority where the priority_map_name is the class map you created for prioritized traffic in "Identifying Traffic for QoS Using Class Maps" section on page 24-6.
For example:
hostname(config)# policy-map priority-sub-policy hostname(config-pmap)# class priority-sub-map hostname(config-pmap-c)# priority
Step 2 To add or edit a policy map for traffic shaping, enter the following command:
hostname(config)# policy-map name
For example:
Creating a Policy for Traffic Shaping and Hierarchical Priority Queueing I
hostname(config)# policy-map shape policy
Step 3 To configure traffic shaping, enter the following commands:
hostname(config-pmap)# class class-default hostname(config-pmap-c)# shape average rate [burst_size]
where the average rate argument sets the average rate of traffic in bits per second over a given fixed time period, between 64000 and 154400000. Specify a value that is a multiple of 8000. See the "Traffic Shaping Overview" section on page 24-4 for more information about how the time period is calculated.
The burst_size argument sets the average burst size in bits that can be transmitted over a given fixed time period, between 2048 and 154400000. Specify a value that is a multiple of 128. If you do not specify the burst_size, the default value is equivalent to 4-milliseconds of traffic at the specified average rate. For example, if the average rate is 1000000 bits per second, 4 ms worth = 1000000 * 4/1000 = 4000.
You can only identify the class-default class map, which is defined as match any, because the security appliance requires all traffic to be matched for traffic shaping.
Step 4 (Optional) To configure hierarchical priority queueing, enter the following command:
hostname(config-pmap-c)# service-policy priority_policy_map_name where the priority_policy_map_mme is the policy map you created for prioritized traffic in Step 1. For example:
hostname(config)# policy-map priority-sub-policy hostname(config-pmap)# class priority-sub-map hostname(config-pmap-c)# priority hostname(config-pmap-c)# policy-map shape policy hostname(config-pmap)# class class-default hostname(config-pmap-c)# shape hostname(config-pmap-c)# service-policy priority-sub-policy
Step 5 To activate the policy map on an interface, enter the following command:
hostname(config)# service-policy policymap_name interface interface_name \ _
Note You cannot configure traffic shaping in the global policy.
The following example enables traffic shaping on the outside interface, and limits traffic to 2 Mbps; priority queueing is enabled for VoIP traffic that is tagged with DSCP EF and AF13 and for IKE traffic:
hostname(config)# access-list ike permit udp any any eq 500
hostname(config)# class-map ike hostname(config-cmap)# match access-list ike hostname(config-cmap)# class-map voice_traffic hostname(config-cmap)# match dscp EF AF13
hostname(config-cmap)# policy-map qos class policy hostname(config-pmap)# class voice_traffic hostname(config-pmap-c)# priority hostname(config-pmap-c)# class ike hostname(config-pmap-c)# priority hostname(config-pmap-c)# policy-map qos outside policy hostname(config-pmap)# class class-default hostname(config-pmap-c)# shape average 2000000 16000 hostname(config-pmap-c)# service-policy qos class policy hostname(config-pmap-c)# service-policy qos outside policy interface outside
Continue reading here: Verifying and Monitoring Ctiqbe Inspection
Was this article helpful?