• how to handle DSCP markings for all flows leaving the appliance’s WAN interface, whether the marking is for over-the-WAN or for the LAN on the remote side.
1 The Route Policy checks traffic incoming from the LAN against the MATCH criteria. Entries 10 and 20 don’t match the traffic, but Entry 30 does.
2 The policy applies the entry’s SET actions to the identified flow. In this case, it directs the flow to Tunnel C. Once any traffic matches an entry, no subsequent entries are examined.
3 Before the flow reaches Tunnel C, the QoS Policy checks against its entries and
• assigns the flow to a traffic class. Here, the application, ssh, matches to the pre-defined application group, interactive, so the appliance assigns the flow to Traffic Class 3.
• passes the flow to the Optimization Policy for optimizations, accelerations, and compressions. The Optimization Policy only applies to tunnelized traffic.If the Route Policy’s Set Action is auto-optimized and the local appliance initiates either TCP-based or IP-based handshaking, then the remote appliance determines which tunnel to use, based on information it receives in the first packets from the local appliance.Also, auto-optimization relies on deploying the appliance such that it intercepts outbound and inbound flows. For an out-of-path (Router Mode) appliance, this requires traffic redirection.
1 The Route Policy checks traffic incoming from the LAN against the MATCH criteria in its prioritized entries. Entry 20 matches and designates the flow for pass-through shaped traffic.
• because the flow matched no earlier entries, assigns the flow to the default, Traffic Class 1. Note that the same traffic classes process both optimized and pass-through shaped traffic. Unless you configure pass-through shaped traffic to have a lower maximum bandwidth, the Shaper processes both types of traffic by the same criteria.Note The user interface uses the terminology, pass-through, to refer to pass-through shaped. We use the latter terminology here for clarity.Handling of DSCP markings is further explained in “Applying DSCP Markings to Shaped and Unshaped Pass-through Traffic”.
1
2 The policy applies the entry’s SET actions to the identified flow. In this case, the flow is to be processed as unshaped, pass-through traffic.
3 Because the traffic is set to pass-through unshaped, it is not encapsulated. The QoS Policy checks against its entries and only applies the DSCP marking specified for WAN QoS.
Please send comments or suggestions regarding user documentation to techpubs@silver-peak.com. |