Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Network Security: Firewall, NAT, QoS, IPS and more

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-30-2009, 06:04 PM
Member
 
Join Date: May 2007
Posts: 34
Question Does ASG 7.4 support the QoS bit for traffic going through it?

I've got two cisco switches (3750 & 3560) and I'm about to install (move) an ASG 7.4 in between them. I have lots of VoIP traffic going through the switches with the QoS bit set. The Cisco switches are configured with
Code:
 mls qos trust dscp
 auto qos voip trust
and I need to be sure that the QoS bit for VoIP isn't removed by the ASG 7.4.

I'm not looking to shape the traffic, just to pass it through and have the QoS also go through. The traffic ends up in a WAN router which then will prioritize the traffic between locations.
Reply With Quote
  #2 (permalink)  
Old 06-30-2009, 08:27 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,431
Default

If you are putting the Astaro inline, and have enabled bridging, you should not have a problem; I have a customer that is bridging two segments like his carrying VOIP traffic on a WAN, and the QoS tags remain intact.
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
Reply With Quote
  #3 (permalink)  
Old 07-02-2009, 05:41 PM
Member
 
Join Date: May 2007
Posts: 34
Default

I'm not bridging. Look at the 3750 as my core switches where internet, wan etc are connected on different VLANs. The FW will protect the servers on the 3560 servers, so it will sit between and switches. Some of the servers connected to vlans on 3560 will send/receive voip traffic to and from the wan connection (going to another location of ours). But I need to be sure that the QoS bit (tos) will stay intact (0xb8).

I don't have time at the moment (nor the hardware) to just do the test myself, so thats the reason I'm asking

It's at least positive that it works in bridging... anyone knows about it working in normal FW mode?

As an update to the first post - I've dropped using qos queues - no need on gigabit switch, it's the wan that's the bottleneck (and where qos will be in place). I'm just trusting the ports on the switches now (meaning cisco won't strip the QoS bit (0xb8)):
Code:
mls qos trust dscp
Reply With Quote
Reply

Tags
qos cisco trust dscp asg7

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 06:35 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.