19.07.2013 Views

Enterprise QoS Solution Reference Network Design Guide

Enterprise QoS Solution Reference Network Design Guide

Enterprise QoS Solution Reference Network Design Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 6 IPSec VPN <strong>QoS</strong> <strong>Design</strong><br />

Summary<br />

Version 3.3<br />

Example 6-10 Integrated Unit + Access Model—Cable <strong>Design</strong> Example<br />

!<br />

class-map match-all VOICE<br />

match ip dscp ef ! VoIP<br />

class-map match-any INTERNETWORK-CONTROL<br />

match ip dscp cs6 ! IP Routing<br />

match access-group name IKE ! <strong>Reference</strong>s ISAKMP ACL<br />

class-map match-any CALL-SIGNALING<br />

match ip dscp cs3 ! Old Call-Signaling<br />

match ip dscp af31 ! New Call-Signaling<br />

!<br />

!<br />

policy-map V3PN-TELEWORKER<br />

class VOICE<br />

priority 128 ! Encrypted G.711 over Cable<br />

class INTERNETWORK-CONTROL<br />

bandwidth percent 5 ! Control Plane provisioning<br />

class CALL-SIGNALING<br />

bandwidth percent 5 ! Call-Signaling provisioning<br />

class class-default<br />

fair-queue<br />

queue-limit 30 ! Optional: Anti-Replay Tuning<br />

!<br />

!<br />

policy-map SHAPE-384-CABLE<br />

class class-default<br />

shape average 364800 3640 ! Shapes to 95% of 384 kbps cable link<br />

service-policy V3PN-TELEWORKER ! Nested V3PN Teleworker queuing policy<br />

!<br />

...<br />

!<br />

interface Ethernet0<br />

description Inside Ethernet Interface<br />

ip tcp adjust-mss 542 ! TCP MSS value tuned for slow-link<br />

!<br />

interface Ethernet1<br />

description Outside Ethernet Interface<br />

ip address dhcp<br />

ip tcp adjust-mss 542 ! TCP MSS value tuned for slow-link<br />

service-policy output SHAPE-384-CABLE ! Shaper applied to LAN interface<br />

!<br />

Verification commands:<br />

show policy<br />

show policy interface<br />

<strong>Enterprise</strong> <strong>QoS</strong> <strong>Solution</strong> <strong>Reference</strong> <strong>Network</strong> <strong>Design</strong> <strong>Guide</strong><br />

Summary<br />

IPSec VPNs, the most commonly deployed VPN solutions today, are found in three main contexts:<br />

site-to-site VPNs, teleworker VPNs, and remote-access VPNs. The overlaying of <strong>QoS</strong> technologies on<br />

top of IPSec VPNs is dubbed V3PN, for voice- and video-enabled Virtual Private <strong>Network</strong>s. This chapter<br />

presented considerations and design recommendations for V3PN deployments in site-to-site and<br />

teleworker contexts. A summary of the design recommendations for encryption and <strong>QoS</strong> for site-to-site<br />

and teleworker IPSec V3PNs is illustrated in Figure 6-30.<br />

6-41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!