Configuration QoS on S12700

Created: Feb 2, 2020 03:32:06Latest reply: Feb 10, 2020 07:39:27 215 10 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello,

I'm deploying QoS configuration on S12700. The purpose is remarking DSCP value of packet (network control, voice, critical data) before send to ISP.

Topology:

LAN1 ------------------ S12700 Switch 1 ------------------ ISP ------------------ S12700 Switch 2 ----------------- LAN2

Connection between Sw1 & Sw2 is layer 2 trunking.


I applied config on both switch, but when I capture on WAN interfaces, the DSCP values don't change.


The config that I applied for 2 switches:

acl number 3099

 rule 5 permit ip

 rule 10 permit icmp

 rule 15 permit tcp

 rule 20 permit udp


traffic classifier 3099-c operator or

 if-match acl 3099


traffic behavior 3099-b

 remark dscp af41

 statistic enable


traffic policy 3099-p match-order config

 classifier 3099-c behavior 3099-b


interface GigabitEthernet0/0/1

 description WAN

 port link-type trunk

 port trunk allow-pass vlan 99 101 112 1001

 trust upstream default

 trust dscp


interface GigabitEthernet0/0/2

 description LAN

 port link-type access

 port default vlan 99

 traffic-policy 3099-p inbound

 trust upstream default

 trust dscp


Any help to understand this is much appreciated

  • x
  • convention:

Featured Answers

Recommended answer

chenhui
Admin Created Feb 4, 2020 02:31:11 Helpful(2) Helpful(2)

@Harry101 hi,
please follow the https://support.huawei.com/hedex/hdx.do?docid=EDOC1000135330&id=dc_cfg_qos_0016&lang=en to check the configuration.
please let us if it's helpful to you.
  • x
  • convention:

All Answers
umaryaqub
umaryaqub MVE Created Feb 2, 2020 05:07:40 Helpful(1) Helpful(1)

Hi,

You can get more help from QOS Configuration guide:
https://support.huawei.com/enterprise/en/doc/EDOC1000142089
  • x
  • convention:

Harry101
Harry101 Created Feb 3, 2020 05:41:09
Hi, I followed this guide from the beginning, but it's not work. Do you have any idea?  
A%20network%20professional%20eager%20to%20learn%20and%20help.I%20have%208%20years%20of%20network%20experience%20and%20I%20am%20working%20with%20Huawei%20VAP%20and%20looking%20after%20IP%20Projects%20design.
Harry101
Harry101 Created Feb 2, 2020 05:58:31 Helpful(0) Helpful(0)

Hi, I followed this guide from the beginning, but it's not work. Do you have any idea?
  • x
  • convention:

chenhui
chenhui Admin Created Feb 2, 2020 13:01:21 Helpful(0) Helpful(0)

Posted by Harry101 at 2020-02-02 05:58 Hi, I followed this guide from the beginning, but it's not work. Do you have any idea?
The configuration seems to be fine. Which firmware version does the switch run?
  • x
  • convention:

Harry101
Harry101 Created Feb 3, 2020 05:40:38
Hi Chen,

This is the version
Chassis 1 (Master Switch)
Huawei Versatile Routing Platform Software
VRP (R) software, Version 5.160 (S12700 V200R009C00SPC500)
Copyright (C) 2000-2016 HUAWEI TECH CO., LTD  
Mina1
Mina1 Created Feb 2, 2020 13:32:36 Helpful(0) Helpful(0)

You can get more help from QOS Configuration guide:
https://support.huawei.com/enterprise/en/doc/EDOC1000142089
  • x
  • convention:

Harry101
Harry101 Created Feb 3, 2020 05:41:01
Hi, I followed this guide from the beginning, but it's not work. Do you have any idea?  
chenhui
chenhui Admin Created Feb 4, 2020 02:31:11 Helpful(2) Helpful(2)

@Harry101 hi,
please follow the https://support.huawei.com/hedex/hdx.do?docid=EDOC1000135330&id=dc_cfg_qos_0016&lang=en to check the configuration.
please let us if it's helpful to you.
  • x
  • convention:

Harry101
Harry101 Created Feb 8, 2020 13:17:16 Helpful(0) Helpful(0)

Posted by chenhui at 2020-02-04 02:31 @Harry101 hi,please follow the https://support.huawei.com/hedex/hdx.do?docid=EDOC1000135330&id=dc_cf ...

Hi @chenhui ,

I'm not sure that I am doing with right way, but my expectation is changing the DSCP value of the packet before send to the ISP.

Can you look at my configuration and give some advice.

I upload my full configuration:

SW1:

#

sysname SW1

#

vlan batch 99 101 112 1001

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

diffserv domain default

#

diffserv domain test

ip-dscp-inbound 0 phb af3 green

ip-dscp-inbound 48 phb cs7 green

#

acl number 3099

rule 5 permit ip

rule 10 permit tcp

rule 15 permit icmp

rule 20 permit udp

#

traffic classifier 3099-c operator or

if-match acl 3099

#

traffic behavior 3099-b

remark dscp af43

statistic enable

#

traffic policy 3099-p

classifier 3099-c behavior 3099-b

#

drop-profile default

#

vlan 99

description DATA

#

aaa

authentication-scheme default

authorization-scheme default

accounting-scheme default

domain default

domain default_admin

local-user admin password simple admin

local-user admin service-type http

#

interface Vlanif1

#

interface Vlanif99

ip address 192.168.99.1 255.255.255.0

ospf enable 1 area 0.0.0.0

#

interface Vlanif101

ip address 10.254.0.9 255.255.255.252

ospf network-type p2p

ospf enable 1 area 0.0.0.0

#

interface Vlanif112

ip address 10.254.3.13 255.255.255.240

#

interface MEth0/0/1

#

interface Eth-Trunk21

port link-type trunk

port trunk allow-pass vlan 101 112 1001

stp disable

mode lacp-static

load-balance src-dst-mac

trust upstream default

trust dscp

#

interface GigabitEthernet0/0/1

eth-trunk 21

#

interface GigabitEthernet0/0/2

port link-type access

port default vlan 99

traffic-policy 3099-p inbound

trust upstream default

trust dscp

#

interface GigabitEthernet0/0/3

eth-trunk 21

#

interface GigabitEthernet0/0/4

#

interface GigabitEthernet0/0/5

#

interface GigabitEthernet0/0/6

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

interface LoopBack0

ip address 1.1.1.1 255.255.255.255

ospf enable 1 area 0.0.0.0

#

bgp 65008

router-id 1.1.1.1

peer 10.254.3.14 as-number 65008

#

ipv4-family unicast

undo synchronization

peer 10.254.3.14 enable

#

ospf 1 router-id 1.1.1.1

area 0.0.0.0

#

user-interface con 0

user-interface vty 0 4

#

return




SW2:

#

sysname SW2

#

vlan batch 98 to 99 101 112 1001

#

cluster enable

ntdp enable

ndp enable

#

drop illegal-mac alarm

#

diffserv domain default

#

diffserv domain te

#

diffserv domain test

ip-dscp-inbound 0 phb af3 green

ip-dscp-inbound 48 phb cs7 green

#

acl number 3099

rule 15 permit tcp

rule 20 permit ip

rule 25 permit icmp

rule 30 permit udp

#

traffic classifier 3099-c operator or

if-match acl 3099

#

traffic behavior 3099-b

remark dscp af43

statistic enable

#

traffic policy 3099-p

classifier 3099-c behavior 3099-b

#

drop-profile default

#

aaa

authentication-scheme default

authorization-scheme default

accounting-scheme default

domain default

domain default_admin

local-user admin password simple admin

local-user admin service-type http

#

interface Vlanif1

#

interface Vlanif98

ip address 192.168.98.1 255.255.255.0

ospf enable 1 area 0.0.0.0

#

interface Vlanif101

ip address 10.254.0.10 255.255.255.252

ospf network-type p2p

ospf enable 1 area 0.0.0.0

#

interface Vlanif112

ip address 10.254.3.14 255.255.255.240

#

interface MEth0/0/1

#

interface Eth-Trunk21

port link-type trunk

port trunk allow-pass vlan 101 112 1001

stp disable

mode lacp-static

load-balance src-dst-mac

trust upstream default

trust dscp

#

interface GigabitEthernet0/0/1

eth-trunk 21

#

interface GigabitEthernet0/0/2

port link-type access

port default vlan 98

traffic-policy 3099-p inbound

trust upstream default

trust dscp

#

interface GigabitEthernet0/0/3

eth-trunk 21

#

interface GigabitEthernet0/0/4

#

interface GigabitEthernet0/0/5

#

interface GigabitEthernet0/0/6

#

interface GigabitEthernet0/0/7

#

interface GigabitEthernet0/0/8

#

interface GigabitEthernet0/0/9

#

interface GigabitEthernet0/0/10

#

interface GigabitEthernet0/0/11

#

interface GigabitEthernet0/0/12

#

interface GigabitEthernet0/0/13

#

interface GigabitEthernet0/0/14

#

interface GigabitEthernet0/0/15

#

interface GigabitEthernet0/0/16

#

interface GigabitEthernet0/0/17

#

interface GigabitEthernet0/0/18

#

interface GigabitEthernet0/0/19

#

interface GigabitEthernet0/0/20

#

interface GigabitEthernet0/0/21

#

interface GigabitEthernet0/0/22

#

interface GigabitEthernet0/0/23

#

interface GigabitEthernet0/0/24

#

interface NULL0

#

interface LoopBack0

ip address 2.2.2.2 255.255.255.255

ospf enable 1 area 0.0.0.0

#

bgp 65008

router-id 2.2.2.2

peer 10.254.3.13 as-number 65008

#

ipv4-family unicast

undo synchronization

peer 10.254.3.13 enable

#

ospf 1 router-id 2.2.2.2

area 0.0.0.0

#

user-interface con 0

user-interface vty 0 4

#

return


  • x
  • convention:

chenhui
chenhui Admin Created Feb 10, 2020 07:39:27 Helpful(0) Helpful(0)

Posted by Harry101 at 2020-02-08 13:17 Hi @chenhui ,I'm not sure that I am doing with right way, but my expectation is changing the DSCP ...
Hi @Harry101
it seems that there is no error with the configuration. Please check the DSCP value on the downstream switch, since the traffic mirroring will duplicate the packets before the traffic policy take effect.
If this doesn't help, you might need to contact with the TAC, more information needs to be gathered to locate the problem.
  • x
  • convention:

Comment

Reply
You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

My Followers

Login and enjoy all the member benefits

Login and enjoy all the member benefits

Login