Implementing Quality of Service (QoS) Classification and Marking http://www.INE.com
Copyright © 2010 Internetwork Expert, Inc Module 4 Markings Trust Boundaries NBAR Class-Based Marking Pre-Classification QPPB Classifying and Marking on Catalyst Switches Copyright © 2010 Internetwork Expert, Inc www.INE.com
Pre-Classification Overview QoS for use with GRE and IPSec VPNs An encrypted packet header cannot be read for the QoS marking Copyright © 2010 Internetwork Expert, Inc www.INE.com
Copyright © 2010 Internetwork Expert, Inc ToS Byte Preservation IPSec duplicates the original ToS byte into the new encrypted packet’s header QoS mechanism sees the header and ToS byte just like normal Since 11.3T – this even works with GRE/IPSec tunnels ToS byte copied into GRE header, then into the IPSec header Copyright © 2010 Internetwork Expert, Inc www.INE.com
Copyright © 2010 Internetwork Expert, Inc QoS Pre-classify THIS IS NOT THE ToS BYTE PRESERVATION FEATURE! This allows for QoS classification based on more than just the ToS byte Copyright © 2010 Internetwork Expert, Inc www.INE.com
QoS Pre-classify Con’t A clone is created of all original packet headers; then the clone is used for QoS on the output interface Cloned headers never leave the local router GRE and IPSec are supported Due to performance enhancements – recommended even when all you want to see is the ToS byte Copyright © 2010 Internetwork Expert, Inc www.INE.com
Configuring QoS Pre-classify The qos pre-classify command is all that is needed Restricted to tunnel interfaces (GRE); virtual templates (L2TP); and crypto maps (IPSec) To verify, use show interface or show cryptomap Also, consider verifying the QoS features you have configured Copyright © 2010 Internetwork Expert, Inc www.INE.com