RE: IPSec tunnel throughput [7:20640]

2001-09-21 Thread Kent Hundley

The PIX itself has no imbedded rate-limiting functionality, so if you wanted
to limit traffic streams inbound to the PIX you would need to use some other
tool.  For example, you could front-end the PIX with a router and use CAR to
limit certain traffic streams outbound from the router to the PIX.

Take a look at CAR in the cisco docs and see if it might meet your needs.

http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/qos_
c/qcprt1/qcdcar.htm

You can limit traffic based on access-list matching criteria, so you could
limit traffic streams from particular source IP's with AH or ESP as the
protocol.

HTH,
Kent

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of
Eugene Kushnirskiy
Sent: Thursday, September 20, 2001 8:06 PM
To: [EMAIL PROTECTED]
Subject: IPSec tunnel throughput [7:20640]


Is it possible to limit the bandwidth of an IPSec tunnel on a PIX
firewall?


Eugene

[GroupStudy.com removed an attachment of type application/x-pkcs7-signature
which had a name of smime.p7s]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=20686&t=20640
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: IPSec tunnel throughput [7:20640]

2001-09-21 Thread Allen May

Sorry.  PIX does not allow bandwidth modifications.  It would have to be
done at the router outside or inside the PIX on each end.

- Original Message -
From: "Eugene Kushnirskiy" 
To: 
Sent: Thursday, September 20, 2001 10:06 PM
Subject: IPSec tunnel throughput [7:20640]


> Is it possible to limit the bandwidth of an IPSec tunnel on a PIX
> firewall?
>
>
> Eugene
>
> [GroupStudy.com removed an attachment of type
application/x-pkcs7-signature
> which had a name of smime.p7s]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=20688&t=20640
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]