DSCP Marking on the IPv4 frame within a VXLAN interface
Hi,
I haven't found anything online relating to this so thought I might ask here if anyone has come across a way to do it,
Currently I am testing a VXLAN tunnel running between 2 Fortigate 60F firewalls connected on Port1 (internal1) with a VXLAN interface (vn1000) attached to a software switch along with internal3 connected to a PC within the same IP subnet (192.168.1.x) on each firewall,
The PC's are able to ping successfully so the VXLAN tunnel is operating correctly, but I wish to attach a DSCP Marking to the VXLAN traffic (CS6, binary: 110 000),
This is currently what I'm seeing through Wireshark:

I have applied DSCP at the the Traffic Shaper 'high-priority' and applied it to the Traffic Shaping Policy 'DSCP_Internal1_SW1'

 

 
I believe this is preforming the marking only at the layer 3 level so my question is can I add a DSCP marking at the VXLAN interface or directly to the traffic itself when it enters the switch and leaves marked at CS6?
It might be good to note I am currently running both FortiGates on the 7.4.7 firmware version,
If anyone has experience with the topic I'd appreciate the help!
Thanks!
 
