Hi all, I have an uncommon situation and would like Cisco’s take on it.As per the above diagram
We have a requirement where we need to classify and mark traffic on the egress (on the CE routers).
The transmission media for this traffic is PPPoE. This PPPoE transmission is via RF and get’s terminated on the ISP PE routers (as per attached figure).
Once we have L3 reachability between CE sites we build GRE tunnels from the hub site (C) to the two spokes (A & B). Over the GRE we run IPSec . Inside IPSec we enable BGP.
Our egress classification and marking is meant to be acknowledged and prioritised by the ISP, as you can see this traffic is within two tunnels - can this be done? Assuming both us & the ISP are using Cisco devices running code 12.4 or higher.
Firstly, I'm not from Cisco Neither the information i have provided below is a view of Cisco.
IMHO, this is not possible. The reason is, your packet is already encrypted & gets inside the tunnel. Your ISP is just a transit path for you thats all. Not sure as to why you would like your ISP to respect your marking when you have a tunnel going on between sites? You need QoS between your sites, so you can keep your ISP apart from it.
Right. End-to-End QoS would be between your sites within the GRE tunnel. So, ISP wouldn't know as the QoS marking would be encapsulated as well within the GRE header.
So frankly speaking, you must not bother about the ISP's involvement to have your markings acknowledged. Remember, you are running GRE, so you would have the End-to-End QoS between your endpoints only.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...