I have 2 3560's that are distrobution layer devices that aggregate serveral access layer switches in one of our offices. I want these switches to simply pass the ingress tagged QoS packets on out to our core network unchanged and retaining the original QoS value that was given in the access layer. Right now I have mls qos trust dscp configured on each trunk interface, but I'm just curious, if I use the global command "no mls qos rewrite ip dscp" would that allow me to not have to add the trust command on the trunk interface. From what I'm gathering from the configuration guide this tag will stop the switch from changing any QoS value by default. So if that is the case an untrusted interface won't set the CoS to 0 for example. Am I understanding this correctly?