cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3000
Views
0
Helpful
6
Replies

Cisco ASA VPN QoS

vttendere
Level 1
Level 1

Hi

Does the ASA copy the ToS byte from the original packet into the newly created IP header of an encrypted packet (VPN)? I'd appreciate a pointer to a Cisco doc that has the details.

Thanks

1 Accepted Solution

Accepted Solutions

On the ASA the TOS bits in the original IP header are copied to the IP header of the encrypted packet so that QoS policies can be enforced after encryption.

It is done by default with no extra commands needed as on the routers.

Please check if your incoming packet have the DSCP bits set if you see that there are no DSCP on the outside.

PK

View solution in original post

6 Replies 6

andrew.prince
Level 10
Level 10

Along with the link that Andrew sent I would like to add that the ASA maintains and copies the ToS field

.

And provide one more link to help you do QoS on the ASA https://supportforums.cisco.com/docs/DOC-1230

I hope it helps.

PK

Hi

Thanks for your response. I had actually configured QoS on the ASA, however when I was sniffing traffic after the ASA I noticed that the traffic traversing the VPN (ESP packets) had DSCP DEFAULT markings, so I was a bit concerned about the preservation of the TOS information. I thought that maybe there is an extra command I need to put, I cant see this in the doc you sent me though.

Thanks guys

On the ASA the TOS bits in the original IP header are copied to the IP header of the encrypted packet so that QoS policies can be enforced after encryption.

It is done by default with no extra commands needed as on the routers.

Please check if your incoming packet have the DSCP bits set if you see that there are no DSCP on the outside.

PK

Hi

Indeed traffic coming into the ASA was not marked correctly.

Thanks a lot for your assistance.

I am glwe could  out.

Take care,

PK

Review Cisco Networking for a $25 gift card