08-18-2015 05:07 AM - edited 03-08-2019 01:23 AM
Hi All,
I have a site with 6 Cisco 300 switches, all running basic out-of-the-box QoS for VOIP phones, trusting the DSCP.
SW6Stephenville-300A#show qos
Qos: Basic mode
Basic trust: dscp
These 6 switches all run back to a Cisco 3650 core switch, and then into an ASA which VPN's everything to the data center for centralized services.
My question is: Do I need to configure any sort of QoS on the core 3650 switch to ensure the VOIP still gets prioity once VOIP traffic from access layer comes into the core switch & goes up to the router/firewall? This switch is IOS-XE, so it is auto qos, not mls. Or is it enough to just have the QOS configured as it is on the 300 switches? I have come across documentation that says you should put auto qos voip trust on the switch uplinks and the firewall uplinks, and then I've come across other documentation says that as long as the QOS is applied on the access layer switches (the 300's), then QOS will be carried and applying further QOS on uplinks in the distribution layer will cause everything to have QOS, which defeats the purpose.
Can someone advise? Thanks.
Solved! Go to Solution.
08-18-2015 08:39 AM
Qos on 3650/3850 is on by default trusting dscp , I didn't enable anything, I have a lod of 29s,37s, behind these trusting at source of the phone , checked it with TAC to be sure and you can also run a wireshark to confirm your markings are ok
You can check with this command
show platform qos dscp-cos counters gigabitEthernet x/x
wan-interconnect#show platform qos dscp-cos counters gigabitEthernet 1/0/1
Ingress DSCP0 21776485364 0
Ingress DSCP1 1232408 0
Ingress DSCP2 93955752 0
Ingress DSCP3 4018 0
Ingress DSCP4 1194175999 0
Ingress DSCP5 10 0
Ingress DSCP6 2 0
Ingress DSCP7 3751 0
Ingress DSCP8 87076823 0
Ingress DSCP9 19 0
Ingress DSCP10 115202 0
Ingress DSCP11 1 0
Ingress DSCP12 5 0
Ingress DSCP13 0 0
Ingress DSCP14 1 0
Ingress DSCP15 0 0
Ingress DSCP16 258 0
Ingress DSCP17 0 0
Ingress DSCP18 64591685 0
Ingress DSCP19 0 0
Ingress DSCP20 0 0
Ingress DSCP21 1 0
Ingress DSCP22 0 0
Ingress DSCP23 0 0
Ingress DSCP24 286364821 0
Ingress DSCP25 1 0
Ingress DSCP26 16089585 0
Ingress DSCP27 1 0
Ingress DSCP28 3 0
Ingress DSCP29 0 0
Ingress DSCP30 0 0
Ingress DSCP31 0 0
Ingress DSCP32 1 0
Ingress DSCP33 0 0
Ingress DSCP34 103410714 0
Ingress DSCP35 0 0
Ingress DSCP36 3 0
Ingress DSCP37 0 0
Ingress DSCP38 0 0
Ingress DSCP39 0 0
Ingress DSCP40 26709605 0
Ingress DSCP41 0 0
Ingress DSCP42 5 0
Ingress DSCP43 0 0
Ingress DSCP44 0 0
Ingress DSCP45 2 0
Ingress DSCP46 389074085 0
Ingress DSCP47 5 0
Ingress DSCP48 33155783 0
Ingress DSCP49 1369 0
Ingress DSCP50 667148 0
Ingress DSCP51 10 0
Ingress DSCP52 1603 0
Ingress DSCP53 74 0
Ingress DSCP54 1180 0
Ingress DSCP55 20 0
Ingress DSCP56 5527 0
Ingress DSCP57 4021 0
Ingress DSCP58 44 0
Ingress DSCP59 7 0
Ingress DSCP60 6202 0
Ingress DSCP61 4370 0
Ingress DSCP62 38 0
Ingress DSCP63 7 0
Ingress COS0 24074613282 0
Ingress COS1 0 0
Ingress COS2 0 0
Ingress COS3 0 0
Ingress COS4 0 0
Ingress COS5 0 0
Ingress COS6 0 0
Ingress COS7 0 0
Egress DSCP0 33350262626 0
Egress DSCP1 719285 0
Egress DSCP2 406304379 0
Egress DSCP3 4654 0
Egress DSCP4 45988524 0
Egress DSCP5 0 0
Egress DSCP6 37 0
Egress DSCP7 3 0
Egress DSCP8 191448540 0
Egress DSCP9 0 0
Egress DSCP10 5416849714 0
Egress DSCP11 4 0
Egress DSCP12 25 0
Egress DSCP13 0 0
Egress DSCP14 1 0
Egress DSCP15 3 0
Egress DSCP16 2772719 0
Egress DSCP17 2 0
Egress DSCP18 817410367 0
Egress DSCP19 5 0
Egress DSCP20 560 0
Egress DSCP21 1 0
Egress DSCP22 113 0
Egress DSCP23 1 0
Egress DSCP24 908044757 0
Egress DSCP25 3 0
Egress DSCP26 34742743 0
Egress DSCP27 3 0
Egress DSCP28 4927 0
Egress DSCP29 2 0
Egress DSCP30 0 0
Egress DSCP31 2 0
Egress DSCP32 7281544 0
Egress DSCP33 1 0
Egress DSCP34 101106283 0
Egress DSCP35 3 0
Egress DSCP36 3 0
Egress DSCP37 0 0
Egress DSCP38 27122 0
Egress DSCP39 3 0
Egress DSCP40 84967830 0
Egress DSCP41 0 0
Egress DSCP42 38 0
Egress DSCP43 1 0
Egress DSCP44 15 0
Egress DSCP45 4 0
Egress DSCP46 761624833 0
original response from TAC
As I mentioned you on the last email and according to Cisco Documentation the 3850 switch has enabled by default QoS, trust interfaces and Classification. Therefore, you do not have to enable it. I would like to highlight that each switch platform is independent in terms of HW and SW.
Therefore, some configurations and the default behaviour are different between them.
08-18-2015 08:39 AM
Qos on 3650/3850 is on by default trusting dscp , I didn't enable anything, I have a lod of 29s,37s, behind these trusting at source of the phone , checked it with TAC to be sure and you can also run a wireshark to confirm your markings are ok
You can check with this command
show platform qos dscp-cos counters gigabitEthernet x/x
wan-interconnect#show platform qos dscp-cos counters gigabitEthernet 1/0/1
Ingress DSCP0 21776485364 0
Ingress DSCP1 1232408 0
Ingress DSCP2 93955752 0
Ingress DSCP3 4018 0
Ingress DSCP4 1194175999 0
Ingress DSCP5 10 0
Ingress DSCP6 2 0
Ingress DSCP7 3751 0
Ingress DSCP8 87076823 0
Ingress DSCP9 19 0
Ingress DSCP10 115202 0
Ingress DSCP11 1 0
Ingress DSCP12 5 0
Ingress DSCP13 0 0
Ingress DSCP14 1 0
Ingress DSCP15 0 0
Ingress DSCP16 258 0
Ingress DSCP17 0 0
Ingress DSCP18 64591685 0
Ingress DSCP19 0 0
Ingress DSCP20 0 0
Ingress DSCP21 1 0
Ingress DSCP22 0 0
Ingress DSCP23 0 0
Ingress DSCP24 286364821 0
Ingress DSCP25 1 0
Ingress DSCP26 16089585 0
Ingress DSCP27 1 0
Ingress DSCP28 3 0
Ingress DSCP29 0 0
Ingress DSCP30 0 0
Ingress DSCP31 0 0
Ingress DSCP32 1 0
Ingress DSCP33 0 0
Ingress DSCP34 103410714 0
Ingress DSCP35 0 0
Ingress DSCP36 3 0
Ingress DSCP37 0 0
Ingress DSCP38 0 0
Ingress DSCP39 0 0
Ingress DSCP40 26709605 0
Ingress DSCP41 0 0
Ingress DSCP42 5 0
Ingress DSCP43 0 0
Ingress DSCP44 0 0
Ingress DSCP45 2 0
Ingress DSCP46 389074085 0
Ingress DSCP47 5 0
Ingress DSCP48 33155783 0
Ingress DSCP49 1369 0
Ingress DSCP50 667148 0
Ingress DSCP51 10 0
Ingress DSCP52 1603 0
Ingress DSCP53 74 0
Ingress DSCP54 1180 0
Ingress DSCP55 20 0
Ingress DSCP56 5527 0
Ingress DSCP57 4021 0
Ingress DSCP58 44 0
Ingress DSCP59 7 0
Ingress DSCP60 6202 0
Ingress DSCP61 4370 0
Ingress DSCP62 38 0
Ingress DSCP63 7 0
Ingress COS0 24074613282 0
Ingress COS1 0 0
Ingress COS2 0 0
Ingress COS3 0 0
Ingress COS4 0 0
Ingress COS5 0 0
Ingress COS6 0 0
Ingress COS7 0 0
Egress DSCP0 33350262626 0
Egress DSCP1 719285 0
Egress DSCP2 406304379 0
Egress DSCP3 4654 0
Egress DSCP4 45988524 0
Egress DSCP5 0 0
Egress DSCP6 37 0
Egress DSCP7 3 0
Egress DSCP8 191448540 0
Egress DSCP9 0 0
Egress DSCP10 5416849714 0
Egress DSCP11 4 0
Egress DSCP12 25 0
Egress DSCP13 0 0
Egress DSCP14 1 0
Egress DSCP15 3 0
Egress DSCP16 2772719 0
Egress DSCP17 2 0
Egress DSCP18 817410367 0
Egress DSCP19 5 0
Egress DSCP20 560 0
Egress DSCP21 1 0
Egress DSCP22 113 0
Egress DSCP23 1 0
Egress DSCP24 908044757 0
Egress DSCP25 3 0
Egress DSCP26 34742743 0
Egress DSCP27 3 0
Egress DSCP28 4927 0
Egress DSCP29 2 0
Egress DSCP30 0 0
Egress DSCP31 2 0
Egress DSCP32 7281544 0
Egress DSCP33 1 0
Egress DSCP34 101106283 0
Egress DSCP35 3 0
Egress DSCP36 3 0
Egress DSCP37 0 0
Egress DSCP38 27122 0
Egress DSCP39 3 0
Egress DSCP40 84967830 0
Egress DSCP41 0 0
Egress DSCP42 38 0
Egress DSCP43 1 0
Egress DSCP44 15 0
Egress DSCP45 4 0
Egress DSCP46 761624833 0
original response from TAC
As I mentioned you on the last email and according to Cisco Documentation the 3850 switch has enabled by default QoS, trust interfaces and Classification. Therefore, you do not have to enable it. I would like to highlight that each switch platform is independent in terms of HW and SW.
Therefore, some configurations and the default behaviour are different between them.
08-18-2015 08:53 AM
Perfect. Thanks Mark.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide