Created on 04-28-2022 04:38 AM Edited on 02-05-2024 06:49 AM By Stephen_G
This article provides some examples regarding the use of TOS and DSCP code forwarding in a firewall policy.
It expands on the article available here.
Understanding basic scenarios regarding traffic prioritization in FortiGate.
ToS/DSCP: 8bit ToS field in IP header = 6bit DSCP + 2bit unused.
DSCP code is a 6bit identification code used to prioritize the traffic.
Additional data about the standard codes used is not vendor-specific. Here is another article that describes these codes in more detail.
FortiGate handles DSCP markings in a few places:
- Firewall policies (described in this article).
- Firewall traffic-shaper.
- Firewall shaping-policy.
It can happen that all 3 marking settings can be applied to the same traffic.
Priority is as follows:
- Firewall policy (least priority).
- Traffic shaping-policy overrides firewall policy.
- Traffic-shaper overrides both traffic shaping-policy and firewall policy.
Firewall policy handles the marking only (allow/deny/change it).
Traffic shaper / shaping policy is actually the one prioritizing the traffic (dropping if needed).
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.