<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exclude traffic from crypto map based on DSCP/IP precedence values in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/exclude-traffic-from-crypto-map-based-on-dscp-ip-precedence/m-p/2931138#M909541</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to configure an IPsec connection which excludes some traffic from being encripted using its dscp value. Apparently it's as easy as configuring its dscp value with a deny statement on the crypto ACL , but it's not working. Sometimes it encripts the traffic and sometimes it drops it, depending on the configuration. I need to configure a "deny tcp/udp any any" at the top of the ACL since the same source network could generate some traffic to be encripted and some not to be (skype, voip, etc...).My goal is to get something like this to work:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list 2285 deny udp any any dscp ef&lt;BR /&gt;access-list 2285 deny udp any any dscp af41&lt;/P&gt;
&lt;P&gt;access-list 2285&amp;nbsp;permit &amp;lt;nerwork_1&amp;gt; &amp;lt;network_2&amp;gt;&lt;/P&gt;
&lt;P&gt;(...)&lt;BR /&gt;&lt;SPAN&gt;access-list 2285&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;permit &amp;lt;nerwork_y&amp;gt; &amp;lt;network_z&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If I use deny statements without "any any" but with "network_a network_b" it works but there are so many networks (and more to be deployed) that the "any any" are needed. I'm using a Cisco 3925 with IOS 15.4(3)M3 but I've also tested some other older IOS with the same results.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any help/advice? Thanks, Best regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;José Manuel.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:57:08 GMT</pubDate>
    <dc:creator>MysticalTh0r</dc:creator>
    <dc:date>2020-02-21T13:57:08Z</dc:date>
    <item>
      <title>Exclude traffic from crypto map based on DSCP/IP precedence values</title>
      <link>https://community.cisco.com/t5/network-security/exclude-traffic-from-crypto-map-based-on-dscp-ip-precedence/m-p/2931138#M909541</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to configure an IPsec connection which excludes some traffic from being encripted using its dscp value. Apparently it's as easy as configuring its dscp value with a deny statement on the crypto ACL , but it's not working. Sometimes it encripts the traffic and sometimes it drops it, depending on the configuration. I need to configure a "deny tcp/udp any any" at the top of the ACL since the same source network could generate some traffic to be encripted and some not to be (skype, voip, etc...).My goal is to get something like this to work:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list 2285 deny udp any any dscp ef&lt;BR /&gt;access-list 2285 deny udp any any dscp af41&lt;/P&gt;
&lt;P&gt;access-list 2285&amp;nbsp;permit &amp;lt;nerwork_1&amp;gt; &amp;lt;network_2&amp;gt;&lt;/P&gt;
&lt;P&gt;(...)&lt;BR /&gt;&lt;SPAN&gt;access-list 2285&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;permit &amp;lt;nerwork_y&amp;gt; &amp;lt;network_z&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If I use deny statements without "any any" but with "network_a network_b" it works but there are so many networks (and more to be deployed) that the "any any" are needed. I'm using a Cisco 3925 with IOS 15.4(3)M3 but I've also tested some other older IOS with the same results.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any help/advice? Thanks, Best regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;José Manuel.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:57:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exclude-traffic-from-crypto-map-based-on-dscp-ip-precedence/m-p/2931138#M909541</guid>
      <dc:creator>MysticalTh0r</dc:creator>
      <dc:date>2020-02-21T13:57:08Z</dc:date>
    </item>
  </channel>
</rss>

