The point of the qos pre-classify command is to be able to read and manipulate the IP header
of a packet going through a VPN.
The problem is that when a packet enters a VPN it is encrypted, header and all.
After this command is applied, the router makes a copy of the original IP header so that you can
perform QoS manipulation at egress on an interface.
Actually if the ToS byte (DSCP, ECN or IP Precedence) is the only portion of the header that needs
manipulation. You don’t need qos pre-qualify, however, if you need access to source or destination
ip address or port numbers, then you need the qos pre-qualify command.
Packets entering a router interface, not yet in a VPN tunnel, can be processed with
ingress QoS features on that interface just like always.
Packets exiting a router interface, after encapsulation and encryption by that router into a
VPN tunnel, cannot be processed with egress QoS features on that interface just like always.
The Egress QoS features can only examine the post-encapsulation IP header.
That is why qos pre-classify makes a copy of the original IP header.
The command qos pre-classify turns on pre-classification and is restricted to
tunnel interfaces, virtual templates, and crypto maps,
it is not available on any other interface type.
Apply the policy to a physical interface and enable qos-preclassify on a tunnel interface
when you want to classify packets based on the pre-tunnel header.
Cisco recommends Preclassify over simple ToS Preservation anytime you want to match on
the ToS byte only, or the ToS byte and other parameters like Source and Destination ports,
Preclassify is always recommended in Security/QoS environments.
QoS for VPNs feature. This feature is enabled with the qos pre-classify.
Remember that a packet is encrypted in the vpn process, so the pre-clasify will mark the packets
so they can apply the service policy and prioritise voice,video or whatever traffic.
I performed a packet capture, and, as expected, i only see :
ESP packets with the DSCP value set at 0.
Place qos pre-classify command in the crypto map.
crypto map vpn 10 ipsec-isakmp
qos pre-classify
These are the guidelines for implementing QoS :
- Classify and mark as close to the source as possible.
- Police traffic as close to the source as possible.
- Establish proper trust boundaries.
- Classify and mark real-time voice and video as high-priority traffic.
- Use multiple queues on transmit interfaces.
- Try to perform hardware-based rather software-based QoS.
Control Plane Policing
The control plane of a Cisco router includes the data plane, management plane and service plane.
Control plane policing allows you to build QoS filters to protect the router against DoS attacks.
Comments
(There are currently no comments for this post.)