cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
435
Views
0
Helpful
1
Replies

IP precedence changing across WAN link

                   Our IP WAN uses Telstras IPWAN MPLS network, We have a server that we set the DSCP markings to AF31( precedence flash)

now all the packets leaving the head end are correctly marked, but when they arrive at the branch about 25% of the packets have lost their markings and is set back to 0. Now telstra have checked their network and see the packets correctly marked. This only leaves their Switch on site and our 3945 router

Now the question is: is there anyway input packets on a3945 Gigabit interface can change the markings on packets?

Note only one site exhibits this problem out of 15 with 3945 routers and same config.

see relevent config below

Head office IPWAN  config.

interface GigabitEthernet0/2

bandwidth 80000

ip address 172.28.4.254 255.255.255.252

ip access-group 190 out

ip wccp 62 redirect in

ip flow ingress

ip flow egress

tx-ring-limit 64

tx-queue-limit 64

duplex auto

speed auto

service-policy output QOS_OUT_NEW

Branch IPWAN config

interface GigabitEthernet0/2

description FNN N3819428R IPWAN

bandwidth 4000

ip address 172.28.29.254 255.255.255.252

glenelgip access-group 190 in

ip wccp 62 redirect in

ip flow monitor Monitor-FNF input

ip flow monitor Monitor-FNF output

tx-ring-limit 64

tx-queue-limit 64

duplex full

speed 100

service-policy output 4Mbps

Access-list 190 at head office

sh access-l 190

Extended IP access list 190

    10 permit ip host 172.16.94.5 any precedence routine

    20 permit ip host 172.16.94.5 any precedence priority

    30 permit ip host 172.16.94.5 any precedence immediate

    40 permit ip host 172.16.94.5 any precedence flash (5764 matches)

    50 permit ip host 172.16.94.5 any precedence flash-override

    60 permit ip host 172.16.94.5 any precedence critical

    70 permit ip host 172.16.94.5 any precedence internet

    80 permit ip host 172.16.94.5 any precedence network

    90 permit ip host 172.16.94.5 any

    100 permit ip any any (1055808 matches)

Access-list 190 at branch

Extended IP access list 190

    10 permit ip host 172.16.94.5 any precedence routine (1888 matches)

    20 permit ip host 172.16.94.5 any precedence priority

    30 permit ip host 172.16.94.5 any precedence immediate

    40 permit ip host 172.16.94.5 any precedence flash (3852 matches)

    50 permit ip host 172.16.94.5 any precedence flash-override

    60 permit ip host 172.16.94.5 any precedence critical

    70 permit ip host 172.16.94.5 any precedence internet

    80 permit ip host 172.16.94.5 any precedence network

    90 permit ip host 172.16.94.5 any

    100 permit ip any any (80444 matches)

1 Reply 1

daniel.dib
Level 7
Level 7

Can you show us the policy-maps as well?

What did the service provider say? How did they test it? Is it possible you are filling up your quota and some packets get remarked due to policer at SP?

Daniel Dib
CCIE #37149

Please rate helpful posts.

Daniel Dib
CCIE #37149
CCDE #20160011

Please rate helpful posts.
Review Cisco Networking products for a $25 gift card