cancel
Showing results for 
Search instead for 
Did you mean: 

QoS over VPN tunnel

BS
Here to help

QoS over VPN tunnel

Hey all,

 

Is anyone here use QoS on MX devices through VPN tunnel to traffic shape Voice and video?

Can you guys share your experiences, any challenges and suggestions?

 

BS

3 REPLIES
A model citizen

Re: QoS over VPN tunnel

Yup. I basically just apply the defaults that they came out with few months back. As long as both sides of the tunnel have it, they will honor the markings they receive (assuming your applications are marking).
Nolan Herring | nolanwifi.com
TwitterLinkedIn
Head in the Cloud

Re: QoS over VPN tunnel

First off you should realize that it doesn't matter what you mark your traffic when you are sending it in a VPN over the Internet. The Internet doesn't respect your markings. It laughs at your markings. It spits on the ground in front of your markings. It farts in the general direction of your markings. 

 

Smiley Wink

 

But, for inside your own network, what @NolanHerring says is bang on. Well... Almost bang on, depending on what version of firmware you're running. As of version 14.5:

 

image.png

And then tweaked just a touch in version 14.6:

 

image.png

 

In our testing this has worked exactly as described. So at the end of the day, for Voice payload, as long as your end points are marking their traffic correctly and your switches trust those markings (or if you're marking on switch port ingress) you don't actually need to do anything on the MX. It's already doing it. 

 

Video is obviously not covered here as it shouldn't be marked EF, so normal rules apply. 

Kind of a big deal

Re: QoS over VPN tunnel

AutoVPN will preserve the DSCP markings of packets entering and leaving the AutoVPN tunnel - but will not act on it in anyway.  More specifically, traffic flowing over an AutoVPN tunnel does not recieve any special treament.

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/QoS_over_a_Site-to-site_VPN