cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1160
Views
0
Helpful
2
Replies

Default Trust Behavior - 2960x, 3850

keith.holder
Level 1
Level 1

I've searched the web and the forums but can't find the answer to my question.  Hopefully someone can fill me in.  If I don't configure QoS on a 2960x or 3850, what is the default behavior in regards to dscp/cos markings arriving to the switch from an IP phone and/or access point?  I know trust boundaries will re-mark frames but how about out of the box behavior?

1 Accepted Solution

Accepted Solutions

Mark Malone
VIP Alumni
VIP Alumni

Hey

2960s do not trust by default , 3850s and nx-os trust dscp by default , so if you have a phone that's marking as DSCP46 you don't need to do anything on 3850 but on 2960 your better off applying something like mls qos trust dscp on access and uplinks to carry marking , you can see this using a wireshark on ingress/egress of switches

This is the command on 3850 to check DSCVP is being carried without any config applied

3850A#show platform qos dscp-cos counters gigabitEthernet 1/1/1
Ingress DSCP0 821967846     0
Ingress DSCP1 759           0
Ingress DSCP2 2216187       0
Ingress DSCP3 361           0
Ingress DSCP4 2610920       0
Ingress DSCP5 0             0
Ingress DSCP6 3             0
Ingress DSCP7 1             0
Ingress DSCP8 1886584       0
Ingress DSCP9 0             0
Ingress DSCP10 16257         0
Ingress DSCP11 10            0
Ingress DSCP12 4             0
Ingress DSCP13 2             0
Ingress DSCP14 0             0
Ingress DSCP15 0             0
Ingress DSCP16 124248        0
Ingress DSCP17 0             0
Ingress DSCP18 3049540       0
Ingress DSCP19 0             0
Ingress DSCP20 0             0
Ingress DSCP21 0             0
Ingress DSCP22 0             0
Ingress DSCP23 0             0
Ingress DSCP24 1426281       0
Ingress DSCP25 0             0
Ingress DSCP26 21627998      0
Ingress DSCP27 0             0

View solution in original post

2 Replies 2

Mark Malone
VIP Alumni
VIP Alumni

Hey

2960s do not trust by default , 3850s and nx-os trust dscp by default , so if you have a phone that's marking as DSCP46 you don't need to do anything on 3850 but on 2960 your better off applying something like mls qos trust dscp on access and uplinks to carry marking , you can see this using a wireshark on ingress/egress of switches

This is the command on 3850 to check DSCVP is being carried without any config applied

3850A#show platform qos dscp-cos counters gigabitEthernet 1/1/1
Ingress DSCP0 821967846     0
Ingress DSCP1 759           0
Ingress DSCP2 2216187       0
Ingress DSCP3 361           0
Ingress DSCP4 2610920       0
Ingress DSCP5 0             0
Ingress DSCP6 3             0
Ingress DSCP7 1             0
Ingress DSCP8 1886584       0
Ingress DSCP9 0             0
Ingress DSCP10 16257         0
Ingress DSCP11 10            0
Ingress DSCP12 4             0
Ingress DSCP13 2             0
Ingress DSCP14 0             0
Ingress DSCP15 0             0
Ingress DSCP16 124248        0
Ingress DSCP17 0             0
Ingress DSCP18 3049540       0
Ingress DSCP19 0             0
Ingress DSCP20 0             0
Ingress DSCP21 0             0
Ingress DSCP22 0             0
Ingress DSCP23 0             0
Ingress DSCP24 1426281       0
Ingress DSCP25 0             0
Ingress DSCP26 21627998      0
Ingress DSCP27 0             0

Thanks for the quick answer Mark!  I appreciate it.

Review Cisco Networking products for a $25 gift card