cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
266
Views
8
Helpful
1
Replies

DSCP Trusting on Routers..command needed?

zztopping
Level 4
Level 4

I was told that routers automatically trust dscp markings on inbound packets, while switches do not.

Thusly, on catalyst switches you must explicitly enter the trust dscp command on every switch interface where you want to trust dscp(or cos), while on routers, you do not have to do this.

Is this true? My belief is, for security reasons, that you must enter this command on every trusted interface on both Cisco switches AND routers.

1 Accepted Solution

Accepted Solutions

dgahm
Level 8
Level 8

Jonathan,

A router will not re-write DSCP markings unless configured to do so with a policy map. So in that sense routers trust DSCP, but there is no explicit trust DSCP command like switches use.

What effect the DSCP markings have on router egress traffic will depending upon the queuing method applied to the interfaces. WFQ (fair queue) or CBWFQ (class based weighted fair queue), depending on specific configuration, may use DSCP to determine what happens when congestion occurs.

Please rate helpful posts.

Dave

View solution in original post

1 Reply 1

dgahm
Level 8
Level 8

Jonathan,

A router will not re-write DSCP markings unless configured to do so with a policy map. So in that sense routers trust DSCP, but there is no explicit trust DSCP command like switches use.

What effect the DSCP markings have on router egress traffic will depending upon the queuing method applied to the interfaces. WFQ (fair queue) or CBWFQ (class based weighted fair queue), depending on specific configuration, may use DSCP to determine what happens when congestion occurs.

Please rate helpful posts.

Dave

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card