We're running a Cisco 1711 Security Access Router at a corporate satellite office. We make Nortel and Cisco VPN connections from PCs on our internal network out through the router. These VPN connections are starved when a high bandwidth non-VPN (http, ftp, etc.) download is initiated.Can anyone provide any configuration examples (PQ, LLQ, CBWFQ, single-hop QoS, anything that works!) for identifying and prioritizing VPN traffic over all other traffic? The bottleneck is at the router and I should be able to throttle back all other traffic to allow the VPN traffic through. This is a simple problem with a simple solution but I'm finding with Cisco stuff there's no such thing as a simple solution. Please don't send links to Cisco documentation unless it provides an explicit example applying to VPN traffic (no VoIP, etc.) And don't reply saying that QoS won't do any good because it's not implemented on the open internet because all I need is a single hop solution. I had an OpenBSD machine up and running within a few hours as a bandwidth manager (using the built in packet filter) providing the VPN prioritization we needed. We'd still be using it if it were a little more stable with multiple VPN connections.


Reply With Quote

Bookmarks