<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Interesting thanks, so does in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916588#M82539</link>
    <description>&lt;P&gt;Interesting thanks&lt;/P&gt;
&lt;P&gt;I'm running flexconnect&amp;nbsp;mode (centrally switched) for the guest network and my objective is to mark all traffic on this SSID with the AF11 class under the bronze qos profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm also running&amp;nbsp;&lt;SPAN&gt;flexconnect&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;mode (locally&amp;nbsp;switched) for the corp SSID on the&amp;nbsp;silver qos profile&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2016 08:44:41 GMT</pubDate>
    <dc:creator>justin.devos</dc:creator>
    <dc:date>2016-05-24T08:44:41Z</dc:date>
    <item>
      <title>Wireless QOS best practise</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916582#M82533</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have manipulated the QOS bronze class applicable to our wireless Guest network, to 802.1p tag to equal 1 (AF11) on the Cisco&amp;nbsp;WLC configuration - see attached pic. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The silver class applicable to Corp Traffic has been left to default values, so from what I understand will default to a 802.1p tag of 0.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;According to&amp;nbsp;802.1p priority queues:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Value of 1 - will be placed in the Q0 (lowest queue)&lt;/P&gt;
&lt;P&gt;Value of 0 - will be placed in Q1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is actually the desired outcome in our configuration. Do you agree with the above?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Question time:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco recommend s&lt;SPAN&gt;witchports connected to H-REAP/FlexConnect APs with at least one locally switched WLAN should be trunk ports set with the&lt;/SPAN&gt;&lt;SPAN class="apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;mls qos trust cos&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) Does the switchport connected to the wifi AP have to be a trunk? From my understanding 802.1p is&amp;nbsp;essentially&amp;nbsp;the&amp;nbsp;COS value and the COS value can only exist on a 802.1q tagged trunk port? Correct? if so that would suggest the port has to be in trunk mode and not access mode for the marking to be&amp;nbsp;visible? I'm asking because our AP switchports are currently set to access mode and I'm not sure if they need to be trunks?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) If the switchport connected to the AP is configured with the&amp;nbsp;&lt;STRONG&gt;mls qos trust cos&lt;/STRONG&gt;&lt;SPAN class="apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;command is this all the config that is required? Is there any other config required on the&amp;nbsp;lightweight&amp;nbsp;AP as the AP will be doing the marking?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916582#M82533</guid>
      <dc:creator>justin.devos</dc:creator>
      <dc:date>2021-07-05T11:53:52Z</dc:date>
    </item>
    <item>
      <title>1) Does the switchport</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916583#M82534</link>
      <description>&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;1) Does the switchport connected to the wifi AP have to be a trunk?&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;If AP is in Flexconnect mode, then yes, you need to configure switchport as trrunk port. See this post for QoS concerns in that situation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://mrncciew.com/2013/07/23/qos-for-h-reap/"&gt;https://mrncciew.com/2013/07/23/qos-for-h-reap/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If APs are in local mode, then switchport should be in Access port &amp;amp; trusting DSCP is the best practice.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;2) If the switchport connected to the AP is configured with the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;mls qos trust cos&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;command is this all the config that is required? Is there any other config required on the&amp;nbsp;lightweight&amp;nbsp;AP as the AP will be doing the marking?&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;'mls qos trust cos' is required only if you configure that switchport as trunkport &amp;amp; FlexConnect AP connects to it.&lt;/P&gt;
&lt;P&gt;If AP is in loacl mode, read below post for better &amp;nbsp;understanding how QoS work&lt;/P&gt;
&lt;P&gt;&lt;A href="https://mrncciew.com/2012/11/28/understanding-wireless-qos-part-1/"&gt;https://mrncciew.com/2012/11/28/understanding-wireless-qos-part-1/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Again if you are running 8.0 or above code you have some other options as well. Refer this video for more details&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=PhmhIojaEE8"&gt;https://www.youtube.com/watch?v=PhmhIojaEE8&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 04:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916583#M82534</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2016-04-13T04:58:56Z</dc:date>
    </item>
    <item>
      <title>Thanks!! So from verison 7.2</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916584#M82535</link>
      <description>&lt;P&gt;Thanks!! So with version&amp;nbsp;8 (which we are running), what they saying is the 802.1p configuration under the QOS profiles is irrelevant. You just configure trust dscp between your WLC and connected switch, as well as on the&amp;nbsp;trunk interfaces to to wifi access points?&amp;nbsp;That's&amp;nbsp;all you need to do to get basic QOS configured?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 07:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916584#M82535</guid>
      <dc:creator>justin.devos</dc:creator>
      <dc:date>2016-04-13T07:15:34Z</dc:date>
    </item>
    <item>
      <title>Yes, that's correct. Remember</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916585#M82536</link>
      <description>&lt;P&gt;Yes, that's correct. Remember that above video talks about local mode AP operation.&lt;/P&gt;
&lt;P&gt;I would test it in FlexConnect &amp;amp; see how it works prior to trusting DSCP on the AP connected switchport.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 03:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916585#M82536</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2016-04-14T03:00:44Z</dc:date>
    </item>
    <item>
      <title>Just coming back to this</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916586#M82537</link>
      <description>&lt;P&gt;Just coming back to this topic, what if you want your AP to be the starting point of your trust boundary...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So my understanding of our previous discussion and my general understanding of Cisco QOS, first I should clarify:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- if a packet arrives at an AP from a trusted Cisco device - like a Cisco softphone for example the QOS marking will be trusted (if the port is configured with&amp;nbsp;&lt;STRONG&gt;mls qos trust dscp&lt;/STRONG&gt;) and that dscp value will be passed onto the next hop.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- if a packet arrives at an AP from a non Cisco device it will be remarked and put into best effort class of 0?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;next question will be based on the answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 09:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916586#M82537</guid>
      <dc:creator>justin.devos</dc:creator>
      <dc:date>2016-05-23T09:46:47Z</dc:date>
    </item>
    <item>
      <title> - if a packet arrives at an</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916587#M82538</link>
      <description>&lt;PRE class="prettyprint"&gt;&amp;nbsp;- if a packet arrives at an AP from a trusted Cisco device - like a Cisco softphone for example the QOS marking will be trusted (if the port is configured with&amp;nbsp;&lt;STRONG&gt;mls qos trust dscp&lt;/STRONG&gt;) and that dscp value will be passed onto the next hop.&amp;nbsp;&lt;BR /&gt;&amp;nbsp;- if a packet arrives at an AP from a non Cisco device it will be remarked and put into best effort class of 0?&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;AP can't do this. This trust boundary concept available in Cisco catalyst switch platforms &amp;amp; &amp;nbsp;not in AP.&lt;/P&gt;
&lt;P&gt;Also mode AP operate also important from QoS perspective. If AP in FlexConnect mode, then AP will simply drop the traffic to the directly connected switch.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If AP operate in Local mode, then traffic will be tunnel (CAPWAP) back to WLC, so only WLC connected switch will see the IP packet as it is (all interim devices will see capwap encapsulated packets and QoS setting of those headers are derived at the AP for upstream traffic &amp;amp; at the WLC for downstream traffic)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 23:58:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916587#M82538</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2016-05-23T23:58:22Z</dc:date>
    </item>
    <item>
      <title>Interesting thanks, so does</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916588#M82539</link>
      <description>&lt;P&gt;Interesting thanks&lt;/P&gt;
&lt;P&gt;I'm running flexconnect&amp;nbsp;mode (centrally switched) for the guest network and my objective is to mark all traffic on this SSID with the AF11 class under the bronze qos profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm also running&amp;nbsp;&lt;SPAN&gt;flexconnect&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;mode (locally&amp;nbsp;switched) for the corp SSID on the&amp;nbsp;silver qos profile&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 08:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/2916588#M82539</guid>
      <dc:creator>justin.devos</dc:creator>
      <dc:date>2016-05-24T08:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, that's correct. Remember</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/3918303#M82540</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Rasika, just a clarification:&lt;/P&gt;&lt;P&gt;As indicated &lt;A href="https://www.youtube.com/watch?v=PhmhIojaEE8" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;on WLC side (&amp;gt;8.0) we have to trust the controller with:&lt;/P&gt;&lt;PRE&gt;mls qos trust dscp&lt;/PRE&gt;&lt;P&gt;About the AP,&amp;nbsp;if they are central switched:&lt;/P&gt;&lt;PRE&gt;mls qos trust dscp&lt;/PRE&gt;&lt;P&gt;But if they are in &lt;STRONG&gt;FlexConnect&lt;/STRONG&gt; mode, with some SSID&amp;nbsp;with outgoing local traffic (FlexConnect &lt;STRONG&gt;Local Switching&lt;/STRONG&gt; + Central-Auth), and other SSID in Central-Switching.&amp;nbsp;Which is the best choice?&amp;nbsp;Reading &lt;A href="https://mrncciew.com/2013/07/23/qos-for-h-reap/" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;I understand that DSCP trust is still the most appropriate choice (as well the simple CAPWAP traffic on the native VLAN is correctly marked).&lt;/P&gt;&lt;P&gt;What could be the case where Trust DSCP choice is not adequate? (maybe something has changed in these 5 years since the draft of the article)&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 16:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/3918303#M82540</guid>
      <dc:creator>r.nobili1</dc:creator>
      <dc:date>2019-09-03T16:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, that's correct. Remember</title>
      <link>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/3918451#M82541</link>
      <description>&lt;P&gt;Hi Ricardo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For local switching traffic, you have to trust CoS for the switchports those connected to FlexConnect APs.&lt;/P&gt;
&lt;P&gt;Since you have mix of Central Switching SSID &amp;amp; Local Switching SSID, first decide what is most important. If it is central switching, then trust DSCP else CoS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 20:01:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-qos-best-practise/m-p/3918451#M82541</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2019-09-03T20:01:48Z</dc:date>
    </item>
  </channel>
</rss>

