Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Prioritize/Precedence VPN Traffic

Status
Not open for further replies.

Bubbalouie

Technical User
Mar 25, 2009
107
US
Hi,

I have a PIX 506e running Version 6.3(5).

I have 9 site-to-site vpn's terminating on it.

I would like to prioritize the vpn traffic from those sites above other traffic coming in or going out, especially the RDP traffic.

Is there a command in 6.3(5) I can accomplish that with?

Thanks!
 
also, and this is kinda off topic, but...

when i look at the PDM it shows i have 9 ike tunnels and 16 ipsec tunnels. what is the difference between the two? i do have 9 site-to-site vpn's on the PIX.

thanks!
 
you can do policy based routing based on the IP address of the source and/or destination google policy based routing cisco and get tons of examples.

off topic

ike is Internet Key Exchange. your tunnels have pre-shared keys and they are exchanging them so the tunnel remains up, this is phase 1, which includes:
- verify peer
- verify policy (what encryption/hash)
- verify password (pre-shared)

after those 3 have been confirmed, phase 2 begins which is the IPSec tunnel which works at layer 3 in the OSI stack. why you have 9 ike tunnels is for the key exchange portion the 16 IPSec tunnels are the actual VPN tunnel in which data flows through.
 
Yeah, supposed to be getting a full network refresh this year when we move to VoIP system at all locations.

Both vendors have proposed an ASA 5510.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top