PCC + Bandwidth Control for VPN Concentrator

Hello everyone,

I hope you can give me some ideas on this.

Our network is 3 ISPs (15 megabits each) load balanced with PCC.

We have a VPN Concentrator (Cisco ASA 5510) that is Routed through internally, and has a public IP from each ISP.

Our Internal nets 10.0.0.0/8 are natted on the Load Balancer.

We are using 1100AH with ROS 6.1

What I want to do is make some simple queues for the public IP addresses of the VPN Concentrator to be unlimited, and then set a rate limit for our internal nets which is less than the ISP rate, so that there is always some headroom for the VPN Concentrator.

Some tips on the best way to do this would be very helpful,

Thank you,

Alex