Created on 05-28-2024 05:19 AM Edited on 05-28-2024 05:25 AM By Anthony_E
Description | This article describes how to add DSCP tags on FortiOS locally generated traffic. |
Scope | FortiOS v7.4.4. |
Solution |
Consider a scenario where a network administrator has the following topology:
There are multiple spoke devices connected to the Hub FGT via an MPLS network. The administrator wants to prioritize IKE traffic generated via the spoke devices across the ISP's network by injecting DSCP markings on the particular IKE packets.
To do so, the below configuration needs to be applied:
config firewall shaper traffic-shaper edit "QoS_Marking"
config firewall shaping-policy
By performing packet sniffing, it is possible to observe that IKE packets generated by spoke have the DSCP that has been specifically applied:
Internet Protocol Version 4, Src: 10.10.10.10, Dst: 20.20.20.20 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.