Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Maryann135
New Contributor

DSCP Marking on the IPv4 frame within a VXLAN interface

Hi,

 

I haven't found anything online relating to this so thought I might ask here if anyone has come across a way to do it,

 

Currently I am testing a VXLAN tunnel running between 2 Fortigate 60F firewalls connected on Port1 (internal1) with a VXLAN interface (vn1000) attached to a software switch along with internal3 connected to a PC within the same IP subnet (192.168.1.x) on each firewall,

The PC's are able to ping successfully so the VXLAN tunnel is operating correctly, but I wish to attach a DSCP Marking to the VXLAN traffic (CS6, binary: 110 000),

 

This is currently what I'm seeing through Wireshark:

 
 
 
 

DSCP.png

 

I have applied DSCP at the the Traffic Shaper 'high-priority' and applied it to the Traffic Shaping Policy 'DSCP_Internal1_SW1'

DSCP_Internal1_SW1 - Screenshot.png

high-priority Screenshot.png

I believe this is preforming the marking only at the layer 3 level so my question is can I add a DSCP marking at the VXLAN interface or directly to the traffic itself when it enters the switch and leaves marked at CS6?

 

It might be good to note I am currently running both FortiGates on the 7.4.7 firmware version,

 

If anyone has experience with the topic I'd appreciate the help!

 

Thanks!

 

1 REPLY 1
akileshc
Staff
Staff

Hi Maryann,

 

You’ve applied the DSCP marking correctly on the traffic shaper, and your understanding is right — that method only marks the Layer-3 outer IP header. Since VXLAN encapsulates the original frame at Layer-2, the FortiGate does not provide any option to mark the inner VXLAN payload.

 

Fortinet’s DSCP documentation also states that DSCP marking applies only to IP packets handled by a firewall policy/Traffic shaper policy.

 

Technical Tip: Differentiated Services Code Point (DSCP) marking
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Differentiated-Services-Code-Point-DSCP-ma...

 

Regards

Akilesh
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors