I think you need "qos pre-classify" in your "crypto map" configuration.



On Wed, Nov 18, 2009 at 4:08 PM, abdel el anazi <[email protected]>wrote:

>  Hi all,
>
> I stumbled into a real life scenario where I had to avoid congestion on a
> leased line. So I try to use Random Early Detection on an output direction
> the same interface is having a crypto map applied to run ipsec in tunnel
> mode. Now I notice that when I use sh policy-map int fa0/2/0 RED is not
> dropping any traffic and not controlling the burst. I used allot of test
> with Jperf TCP, but dont see any diffrent on the performance when I enable
> RED or disable it.
>
> Is it posible that RED is not detecting the TCP flow becuse of the ipsec?
>
> is there any why to work around this issue.
>
>
> Best Regards
>
>
>
>
>
> ------------------------------
> Express yourself instantly with MSN Messenger! MSN 
> Messenger<http://clk.atdmt.com/AVE/go/onm00200471ave/direct/01/>
>
> _______________________________________________
> For more information regarding industry leading CCIE Lab training, please
> visit www.ipexpert.com
>
>
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to