<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Applying QoS within IPSec and GRE tunnels.. in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978290#M194686</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly, I'm not from Cisco &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; Neither the information i have provided below is a view of Cisco. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO, this is not possible. The reason is, your packet is already encrypted &amp;amp; gets inside the tunnel. Your ISP is just a transit path for you thats all. Not sure as to why you would like your ISP to respect your marking when you have a tunnel going on between sites? You need QoS between your sites, so you can keep your ISP apart from it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jul 2012 13:24:38 GMT</pubDate>
    <dc:creator>Vivek Ganapathi</dc:creator>
    <dc:date>2012-07-03T13:24:38Z</dc:date>
    <item>
      <title>Applying QoS within IPSec and GRE tunnels..</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978289#M194685</link>
      <description>&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Tunnel Diagram&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/6/4/94465-QoS%20setup.jpg" alt="QoS setup.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi all, I have an uncommon situation and would like Cisco’s take on it.As per the above diagram &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a requirement where we need to classify and mark traffic on the egress (on the CE routers). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The transmission media for this traffic is PPPoE. This PPPoE transmission is via RF and get’s terminated on the ISP PE routers (as per attached figure).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we have L3 reachability between CE sites we build GRE tunnels from the hub site (C) to the two spokes (A &amp;amp; B). Over the GRE we run IPSec . Inside IPSec we enable BGP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;The question&lt;/STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our egress classification and marking is meant to be acknowledged and prioritised by the ISP, as you can see this traffic is within two tunnels - can this be done? Assuming both us &amp;amp; the ISP are using Cisco devices running code 12.4 or higher.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thnaks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jit&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 00:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978289#M194685</guid>
      <dc:creator>jitendraanbu</dc:creator>
      <dc:date>2019-03-05T00:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Applying QoS within IPSec and GRE tunnels..</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978290#M194686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly, I'm not from Cisco &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; Neither the information i have provided below is a view of Cisco. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO, this is not possible. The reason is, your packet is already encrypted &amp;amp; gets inside the tunnel. Your ISP is just a transit path for you thats all. Not sure as to why you would like your ISP to respect your marking when you have a tunnel going on between sites? You need QoS between your sites, so you can keep your ISP apart from it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2012 13:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978290#M194686</guid>
      <dc:creator>Vivek Ganapathi</dc:creator>
      <dc:date>2012-07-03T13:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Applying QoS within IPSec and GRE tunnels..</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978291#M194687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello there, thanks for your response. This is exactly how I feel about this as well. It is not doable, as the packets are encrypted &amp;amp; it's transparent to the ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Jit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2012 03:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978291#M194687</guid>
      <dc:creator>jitendraanbu</dc:creator>
      <dc:date>2012-07-04T03:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Applying QoS within IPSec and GRE tunnels..</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978292#M194688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right. End-to-End QoS would be between your sites within the GRE tunnel. So, ISP wouldn't know as the QoS marking would be encapsulated as well within the GRE header. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So frankly speaking, you must not bother about the ISP's involvement to have your markings acknowledged. Remember, you are running GRE, so you would have the End-to-End QoS between your endpoints only. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;*Please rate helpful posts&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2012 04:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978292#M194688</guid>
      <dc:creator>Vivek Ganapathi</dc:creator>
      <dc:date>2012-07-04T04:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Applying QoS within IPSec and GRE tunnels..</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978293#M194689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agai, I agree with you Vivek.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disappointing no one from Cisco has commented on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Jit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2012 05:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/applying-qos-within-ipsec-and-gre-tunnels/m-p/1978293#M194689</guid>
      <dc:creator>jitendraanbu</dc:creator>
      <dc:date>2012-07-04T05:57:51Z</dc:date>
    </item>
  </channel>
</rss>

