Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
prabhueee35
New Contributor II

Fortinet SD WAN 7.4 DSCP

Hi ,

 

I have few firewalls - virtual machines running v7.4.8 all the virtual firewalls are configured with SD WAN rules. This is a SD-WAN setup - Hub & spoke topology.

 

My requirement is DSCP values configured on a Fortigate firewall should be left untouched on other Fortigate firewall. 

 

My setup is a hub and spoke setup. 

 

Can anyone please give practical example of configuring DSCP values on a firewall from Forti manager GUI or FortiGate firewall CLI so that same DSCP values are reflecting on other firewall

5 REPLIES 5
funkylicious
SuperUser
SuperUser

hi,

based on my understanding of the article, DSCP is per policy enabled for traffic. 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Differentiated-Services-Code-Point-DSCP-ma... 

https://docs.fortinet.com/document/fortigate/7.4.8/administration-guide/813032 

this would mean that you would need to set it for traffic on all firewalls, otherwise if not enabled/configured it will be CS0/default when traffic reaches the local FGT.

for FMG, https://docs.fortinet.com/document/fortimanager/7.4.8/administration-guide/812215 

 

"jack of all trades, master of none"
"jack of all trades, master of none"
prabhueee35

Hi for the code v7.4.8 i'm not able to configure the following commands under firewall policy 
 
 
        set diffserv-forward enable
        set diffservcode-forward <binary_integer>
        set diffserv-reverse enable
        set diffservcode-rev <binary_integer>
 
 
Also i'm unable to configure the following commands under shaping-policy 
 
        set diffservcode-forward 011010
 
        set diffservcode-rev 011010
 
set command does not give the above options for both firewall policy and shaping-policy
 
 
can you please help as how do i setup DSCP values in this case
 
funkylicious

they should be there, as per https://docs.fortinet.com/document/fortigate/7.4.8/cli-reference/333889629/config-firewall-policy 

"jack of all trades, master of none"
"jack of all trades, master of none"
prabhueee35

Hi my setup is a  virtual machine - fortigate VM-64 v7.4.8

 

Hence i'm unable to setup diffserv commands. 

 

Are diffserv commands only meant to work on hardware appliances ?

 

If yes can you please give me the equivalent of setting up dscp on Virtual machines

 

Thanks ,

Prabhu

funkylicious

i am unaware of such a limitation.

on a FG-VM that i have access to, i can see the options even tho disabled in the cli

 

config firewall policy

edit <>

show full | grep diff
set diffserv-copy disable
set diffserv-forward disable
set diffserv-reverse disable

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors