D-Link DWS-1008 User Manual
Using the precedence and tos Options
You also can indirectly filter on DSCP by filtering on both the IP precedence and IP ToS values of
a packet. However, this method requires two ACEs. To use this method, specify the combination of
precedence and ToS values that is equivalent to the DSCP value. For example, to filter based on DSCP
value 46, configure an ACL that filters based on precedence 5 and ToS 12. (To display a table of the
precedence and ToS combinations for each DSCP value, use the
show qos dscp-table command.)
The following commands perform the same CoS reassignment as the commands in “Using the dscp
Option”. They remap IP packets from IP address 10.10.50.2 that have DSCP value 46 (equivalent to
precedence value 5 and ToS value 12), to have CoS value 7 when they are forwarded to any 10.10.90.
x address on Distributed AP 4:
DWS-1008#
set security acl ip acl2 permit cos 7 ip 10.10.50.2 0.0.0.0
10.10.90.0 0.0.0.255 precedence 5 tos 12
success: change accepted.
DWS-1008# s
et security acl ip acl2 permit cos 7 ip 10.10.50.2 0.0.0.0
10.10.90.0 0.0.0.255 precedence 5 tos 13
success: change accepted.
DWS-1008#
set security acl ip acl2 permit any
success: change accepted.
DWS-1008#
commit security acl acl2
success: change accepted.
DWS-1008#
set security acl map acl2 dap 4 out
success: change accepted.
The ACL contains two ACEs. The first ACE matches on precedence 5 and ToS 12. The second ACE
matches on precedence 5 and ToS 13. The IP precedence and ToS fields use 7 bits, while the DSCP
field uses only 6 bits. Following the DSCP field is a 2-bit ECN field that can be set by other devices
based on network congestion. The second ACE is required to ensure that the ACL matches regardless
of the value of the seventh bit.
Note: You cannot use the dscp option along with the precedence and tos options in the same ACE.
The CLI rejects an ACE that has this combination of options.
Summary of Contents for DWS-1008
Page 1: ......