Cisco Catalyst SD-WAN Remote Access Configuration Guide, Releases 26.x and Later

PDF

Cisco Catalyst SD-WAN Remote Access Configuration Guide, Releases 26.x and Later

Configure remote access traffic rate limiting

Want to summarize with AI?

Log in

Configure quality of service (QoS) policers and shapers to limit the rate of aggregate upstream and downstream remote access traffic.


You can limit the rate of the aggregate upstream and downstream aggregate remote access traffic by applying quality of service (QoS) policers and shapers.

Remote access traffic rate limiting helps control bandwidth usage and ensure network performance by managing traffic flow between remote access clients and Cisco Catalyst SD-WAN sites.

Procedure

  1. Rate limit remote access upstream traffic (from the remote access client).

    Note

    The upstream traffic may be destined to Cisco Catalyst SD-WAN sites such as the SD-WAN RA headend, a data center LAN, or the internet.

    Use one or both of the following options to rate limit to the required rate.

    • For encrypted upstream traffic: Using Cisco SD-WAN Manager, add an inbound QoS policer on the SD-WAN RA WAN interface, using the local data policy (access list), to rate limit encrypted upstream traffic.

      Rate limiting encrypted traffic drops excess remote access traffic, irrespective of the traffic destination, remote access client type, or application type.

      Configure the following match conditions and action:

      • Match IKEv2 and encrypted IPsec traffic. Include the following:

        • UDP ports 500 and 4500

        • IP protocol ESP

      • Action: Configure the required rate for the policing.

    • For decrypted upstream traffic: Using Cisco SD-WAN Manager, add an inbound QoS policer on the SD-WAN RA WAN interface, using the centralized data policy, to rate limit decrypted upstream traffic.

      When rate limiting decrypted traffic, you can specify remote access clients and application types.

      Note

      SD-WAN RA places a remote access user in a service VPN based on the user identity. After decryption, the traffic from a remote access user is treated as inbound traffic from the VPN of the remote access user.

      Configure the following match conditions and action:

      • Match remote access inner (within the IPsec tunnel) traffic. Specify the following:

        • Remote access user service VPN

        • For the source IP, specify the IP address(es) assigned to the remote access client.

        • Application

      • Action: Configure the required rate for the policing.

  2. Using Cisco SD-WAN Manager, add an inbound QoS policer to the centralized policy to rate limit remote access downstream (toward the remote access client) traffic.

    The traffic may originate from sources such as traffic from the site where the SD-WAN RA headend is located, a data center LAN, software-as-a-service (SaaS) applications, or the internet.

    Effect: This step rate limits the enterprise and internet (including SaaS) remote access return traffic as close as possible to the traffic source (application server). When rate limiting unencrypted traffic, you can specify remote access clients and application types.

    Configure the following match conditions and action:

Remote access traffic is rate limited according to the configured QoS policers, controlling bandwidth usage for both upstream and downstream traffic flows.