Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

QoS hub-spoke IPSec tunnels

$
0
0

Hi all,

 

We have a bunch of remote sites tunneling everything back to a central hub. These remote sites all have various connection speeds/profiles and I'm looking to (specifically) help boost VoIP. I'm using the following but nothing ever seems to get to the voice/premium queues. Our VoIP interface is vlan.101 and our ISP link (not a single physical interface) is vlan.1000. Any ideas? The following is what I'm testing at one of the remote sites.

 

# name classes and set spu/fabric priority
set class-of-service forwarding-classes queue 0 normal priority low
set class-of-service forwarding-classes queue 1 premium priority low
set class-of-service forwarding-classes queue 2 voice priority high
set class-of-service forwarding-classes queue 3 control priority high
# set dscp bits
set class-of-service classifiers dscp v4-classifier forwarding-class normal loss-priority high code-points 000000
set class-of-service classifiers dscp v4-classifier forwarding-class voice loss-priority low code-points 101110
set class-of-service classifiers dscp v4-classifier forwarding-class premium loss-priority medium-low code-points 001100
set class-of-service classifiers dscp v4-classifier forwarding-class control loss-priority high code-points 110000 # create scheduler; highest priority traffic set class-of-service schedulers urgent priority strict-high set class-of-service schedulers urgent transmit-rate percent 5 set class-of-service schedulers urgent buffer-size percent 5 # create scheduler; high priority traffic set class-of-service schedulers high priority high set class-of-service schedulers high transmit-rate percent 5 set class-of-service schedulers high buffer-size percent 5 # create scheduler; medium priority traffic set class-of-service schedulers medium priority medium-low set class-of-service schedulers medium transmit-rate percent 5 set class-of-service schedulers medium buffer-size percent 5 # create scheduler; lowest priority traffic set class-of-service schedulers normal transmit-rate percent 85 set class-of-service schedulers normal buffer-size percent 85 set class-of-service schedulers normal priority low # assign schedulers to forwarding classes set class-of-service scheduler-maps traff-sched forwarding-class normal scheduler normal set class-of-service scheduler-maps traff-sched forwarding-class premium scheduler medium set class-of-service scheduler-maps traff-sched forwarding-class voice scheduler urgent set class-of-service scheduler-maps traff-sched forwarding-class control scheduler high # firewall filter to set traffic to a forwarding-class; 192.168.106.35 is our voip appliance set firewall family inet filter qos term 10 from protocol udp set firewall family inet filter qos term 10 from destination-address 192.168.106.35/32 set firewall family inet filter qos term 10 from port 10000-20000 set firewall family inet filter qos term 10 then forwarding-class voice set firewall family inet filter qos term 10 then accept set firewall family inet filter qos term 20 from destination-address 192.168.106.35/32 set firewall family inet filter qos term 20 from port [ 5060 5061 ] set firewall family inet filter qos term 20 then forwarding-class voice set firewall family inet filter qos term 20 then accept set firewall family inet filter qos term 30 from protocol tcp set firewall family inet filter qos term 30 from port 22 set firewall family inet filter qos term 30 then forwarding-class premium set firewall family inet filter qos term 30 then accept set firewall family inet filter qos term 40 then forwarding-class normal set firewall family inet filter qos term 40 then accept # configure interfaces; shaping-rate will be different at each remote site; vlan 1000 is our ISP connection set class-of-service interfaces vlan unit 1000 classifiers dscp v4-classifier set class-of-service interfaces vlan unit 1000 scheduler-map traff-sched set class-of-service interfaces vlan unit 1000 shaping-rate 5m set interfaces vlan per-unit-scheduler set interfaces vlan unit 1000 family inet filter input qos

 

 


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>