RE: IPSec + LLQ

From: Brian McGahan (bmcgahan@internetworkexpert.com)
Date: Fri Mar 12 2004 - 14:59:52 GMT-3


Richard,

        See if the platform support the "qos pre-classify" command under the
crypto map. This puts the QoS policy behind the crypto engine, as by
default it is after the crypto engine as you have seen. I doubt that this
platform would support it but it's worth a try.

More info:

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fqos
_c/fqcprt1/qcfvpn.htm

HTH,

Brian McGahan, CCIE #8593
bmcgahan@internetworkexpert.com

Internetwork Expert, Inc.
http://www.InternetworkExpert.com
Toll Free: 877-224-8987 x 705
Outside US: 775-826-4344 x 705

> -----Original Message-----
> From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
> Richard Dumoulin
> Sent: Friday, March 12, 2004 10:43 AM
> To: ccielab@groupstudy.com
> Subject: IPSec + LLQ
>
> Hello all,
>
> I am trying to configure a crypto map + CBWFQ on the same interface. I
> would like to prioritise SSH traffic on the output. However, it seems to
> me
> that first the router encrypts and then it classifies !!!
>
> There is an article
> http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/1
> 22
> t/122t13/llqfm.htm that explains another way of doing llq but my router is
> only a 837 :(((
>
> Could anyone confirm my assumption and indicate a way to solve this ?
>
> Thx
>
> --Richard
>
> _______________________________________________________________________
> Please help support GroupStudy by purchasing your study materials from:
> http://shop.groupstudy.com
>
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Thu Apr 01 2004 - 08:15:17 GMT-3