Hi all, I had a customer asking if the MX units copied DSCP markings from the unencrypted IP header to the encrypted UDP packet header. I was happy to find this discussion with some saying yes, and some others saying no. I took the time to set a little lab and I was even happier to see by myself that DSCP tags ARE copied from both already marked traffic ingressing the MX, and traffic that is marked by a custom traffic shaping rule in the MX. I could see the DSCP field with the corresponding class on the encrypted UDP packet in a packet capture. Mystery solved 🙂
... View more