0% found this document useful (0 votes)
2 views15 pages

SchoolSRA QoS Sba

The Schools QoS Deployment Guide outlines the Quality-of-Service (QoS) design principles for the Schools Service Ready Architecture, focusing on the implementation differences between fixed-configuration and modular switching platforms. It emphasizes the importance of prioritizing real-time applications like voice and video while managing lower priority data traffic through differentiated services. The document also details the ingress and egress QoS policies, trust models for endpoints, and specific configurations for Cisco Catalyst switches to optimize network performance and prevent congestion.

Uploaded by

Ahmed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views15 pages

SchoolSRA QoS Sba

The Schools QoS Deployment Guide outlines the Quality-of-Service (QoS) design principles for the Schools Service Ready Architecture, focusing on the implementation differences between fixed-configuration and modular switching platforms. It emphasizes the importance of prioritizing real-time applications like voice and video while managing lower priority data traffic through differentiated services. The document also details the ingress and egress QoS policies, trust models for endpoints, and specific configurations for Cisco Catalyst switches to optimize network performance and prevent congestion.

Uploaded by

Ahmed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Schools QoS Deployment Guide SBA

This document describes the Schools Service Ready Architecture network QoS design While design principles are common, QoS implementation varies between
(see Figure 1). fixed-configuration switches and the modular switching platforms like the Cisco Catalyst
IP networks forward traffic on a best-effort basis by default. The routing protocol forwards 4500/6500. This section discusses the internal switching architecture and the
packets over the best path, but offers no guarantee of delivery. This model works well for differentiated QoS structure on a per-hop-basis.
TCP-based data applications that adapt gracefully to variations in latency, jitter, and loss.
The Schools Service Ready Architecture is a multi service network design which QoS in Catalyst Fixed Configuration Switches
supports voice and video as well as data traffic on a single network. Real-time applications The QoS implementation in Cisco Catalyst 2960, 2975, 3560G, 3560-E, 3750G and
(such as voice, video) require packets delivered with in specified loss, delay and jitter 3750-E Series switches is similar. There is no difference in ingress or egress packet
parameters. Quality-of-Service (QoS) is a collection of features which allows the network classification, marking, queuing and scheduling implementation among these Catalyst
to dedicate network resources for higher priority real time applications, while reserving platforms. The Cisco Catalyst switches allow users to create a policy-map by classifying
sufficient network resources to service lower priority traffic. QoS accomplishes this by incoming traffic (Layer 2 to Layer 4). Catalyst switches allow attaching the policy-map to
providing differentiated services, depending on the traffic type. For a detailed discussion an individual physical port or to logical interfaces (SVI or port-channel). This creates a
of QoS, refer to the Enterprise QoS SRND at the following URL: common QoS policy which may be used in multiple networks. To prevent switch fabric and
[Link] egress physical port congestion, the ingress QoS policing structure can strictly filter
[Link] excessive traffic at the network edge. All ingress traffic from edge ports passes through
the switch fabric and congestion may occur at the egress ports. Congestion in
access-layer switch can be prevented by tuning queuing scheduler and Weighted Tail
Drop (WTD) drop parameters.
Figure 1 Fixed Configuration Catalyst QoS Architecture

Ingress Internal Egress


Policer Marker Queue Ring Queue

Policer Marker Q1
Receive NormalQ Q2 Transmit
Classify SRR Q3 SRR
Priority-Q
Q4
Policer Marker
Policer Marker

227557
Ingress QoS Egress QoS

• Only the Catalyst 3650-E and 3750-E support policing on 10 Gigabit Ethernet
The main difference between these platforms is the switching capacity which ranges interfaces.
from 1G to 10G. The switching architecture and some of the internal QoS structure differs • Only the Catalyst 3650-E and 3750-E support SRR shaping weights on 10 Gigabit
between these switches also. Following are some important differences to consider when Ethernet interfaces
selecting the access switch:
• The Catalyst 2960 and 2975 do not support multilayer switching and do not support QoS in Cisco Modular Switches
per-VLAN or per-port/per-VLAN policies. Cisco Catalyst 4500 and 6500 are high density, resilient switches for large scale networks.
• The Catalyst 2960 and 2975 can police to a minimum rate of 1 Mbps; all other The School Service Ready Architecture uses the Cisco Catalyst 4500 in the district office
switches within this product family can police to a minimum rate of 8 kbps. and larger school site designs; therefore, all the QoS recommendations in this section will
be based on 4500 architecture. Cisco Catalyst 4500 Series platform are widely deployed
• Only the Catalyst 3650-E and 3750-E support IPv6 QoS.
with classic and next-generation supervisors.
Schools QoS Deployment Guide SBA

The classification function in the classic supervisor module is based on incoming DSCP Figure 3 Catalyst 4500 - Supervisor 6-E QoS Architecture
or CoS setting in the pack, which was assigned by the access-layer switches. Catalyst Ingress QoS
4500 with classic supervisor performs ingress and egress QoS function based on internal
Policer Marking
mapping table that performs DSCP, ToS, or CoS interworking. Classic supervisor relies on
Receive Forwarding
trust model configuration; redirection of ingress traffic to an appropriate queue is based Classify
Lookup
on the trust model defined on the edge port. See Figure 2. Unconditional
Marking
Figure 2 Catalyst 4500 - Classic Supervisor QoS Architecture

Egress Egress QoS Q1


Queue Q2
Q1 Policer Marking Q3
Netflow Q2 Queuing/ Transmit
Receive Classify Policer Marker DBL Features Q4 Queuing/ Transmit
Q3 Shaping Classify DBL
SupV-10G Q5 Shaping
Q4 Unconditional Q6
Marking
Q7

227559
227558
Ingress QoS Egress QoS Q8

The Cisco Catalyst 4500 with next generation Sup-6E (see Figure 3) is designed to offer
better differentiated and preferential QoS services for various class-of-service traffic. QoS Framework
New QoS capabilities in the Sup-6E enable administrators to take advantage of QoS needs to be designed and implemented considering the entire network. This
hardware-based intelligent classification and take action to optimize application includes defining trust points, and determining which policies to enforce at each device
performance and network availability. The QoS implementation in Sup-6E supports within the network. Developing the trust model, guides policy implementations for each
Modular QoS CLI (MQC) as implemented in IOS-based routers that overall enhances QoS device.
capabilities and eases implementation and operations. Following are some of the key QoS
features which differentiate the Sup-6E versus classic supervisors: Figure 4 depicts QoS trust model that guides QoS policy implementation in the district
office and school site networks.
• Trust and Table-Map—MQC-based QoS implementation offers a number of
implementation and operational benefits over classic supervisors that rely on Trust Figure 4 School QoS Framework
model and internal Table-map as a tool to classify and mark ingress traffic.
• Internal DSCP—The queue placement in Sup-6E is simplified by leveraging the MQC
capabilities to explicitly map DSCP or CoS traffic in hard-coded egress Queue
structure,. For example, DSCP 46 can be classified with ACL and can be matched in Classification,
Marking and Trust (classic sup)
PQ class-map of an MQC in Sup-6E. Queueing
• Sequential vs Parallel Classification—With MQC-based QoS classification, the
Sup6-E provides sequential classification rather than parallel. Sequential Classification,
classification method allows the network administrator to classify traffic at egress Trust (classic sup) Marking and
Queueing
based on the ingress markings.
Queueing and WTD Trust

Trust, Classification,
Marking, Policing Queueing and WTD
and Queueing

IP

Trusted, Conditional-Trusted or Un-Trusted Endpoints

227560
Trust Boundary Ingress QoS Ploicy Egress QoS Ploicy
Schools QoS Deployment Guide SBA

The devices (routers, switches) within the internal network are managed by the system that the untrusted user behind the endpoint may or may not be secure. For example,
administrator, and hence are classified as trusted devices. Access-layer switches Cisco Unified IP Phone + PC. These deployment scenarios require hybrid QoS
communicate with devices that are beyond the network boundary and within the internal policy that intelligently distinguishes and applies different QoS policy to the trusted
network domain. QoS trust boundary at the access-layer communicates with various and untrusted endpoints that are connected to the same port.
devices that could be deployed in different trust models (Trusted, Conditional-Trusted, or
Un-Trusted). This section discusses the QoS policies for the traffic that traverses Deploying Ingress QoS
access-switch QoS trust boundary. The QoS function is unidirectional; it provides
The ingress QoS policy at the access-switches needs to be established, since this is the
flexibility to set different QoS polices for traffic entering the network versus traffic that is
trust boundary, where traffic enters the network. The following ingress QoS techniques
exiting the network. See Figure 5.
are applied to provide appropriate service treatment and prevent network congestion:
Figure 5 School Network Edge QoS Boundary • Trust—After classifying the endpoint the trust settings must be explicitly set by a
network administrator. By default, Catalyst switches set each port in untrusted mode
when QoS is enabled.
• Classification—IETF standard has defined a set of application classes and provides
Distribution/Core recommended DSCP settings. This classification determines the priority the traffic
will receive in the network. Using the IETF standard, simplifies the classification
process and improves application and network performance.
• Policing—To prevent network congestion, the access-layer switch limits the amount
of inbound traffic up to its maximum setting. Additional policing can be applied for
known applications, to ensure the bandwidth of an egress queue is not completely
Access consumed by one application.
• Marking—Based on trust model, classification, and policer settings the QoS marking
is set at the edge before approved traffic enters through the access-layer switching
fabric. Marking traffic with the appropriate DSCP value is important to ensure traffic is
227561

mapped to the appropriate internal queue, and treated with the appropriate priority.
Ingress QoS Ploicy Egress QoS Ploicy
• Queueing—To provide differentiated services internally in the Catalyst switching
fabric, all approved traffic is queued into priority or non-priority ingress queue.
QoS Trust Boundary Ingress queueing architecture assures real-time applications, like VoIP traffic, are
given appropriate priority (eg transmitted before data traffic).
The access-switch provides the entry point to the network for end devices. The
access-switch must decide whether to accept the QoS markings from each endpoint, or Implementing QoS Trust Mode
whether to change them. This is determined by the QoS policies, and the trust model with
which the endpoint is deployed. By default, QoS is disabled on all Catalyst switches and must be explicitly enabled in
End devices are classified into one of three different trust models; each with it's own global configuration mode. The QoS configuration is the same for a multilayer or
unique security and QoS policies to access the network: routed-access deployment. The following sample QoS configuration must be enabled on
all the access-layer switches deployed in district office and school sites.
• Untrusted—An unmanaged device that does not pass through the network security
cr24-2960-DO(config)#mls qos
policies. For example, student-owned PC or network printer. Packets with 802.1p or
DSCP marking set by untrusted endpoints are reset to default by the access-layer cr24-2960-DO#show mls qos
switch at the edge. Otherwise, it is possible for an unsecured user to take away QoS is enabled
network bandwidth that may impact network availability and security for other users. QoS ip packet dscp rewrite is enabled
• Trusted—Devices that passes through network access security policies and are
managed by network administrator. For example, secure PC or IP endpoints (i.e., Upon enabling QoS in the Catalyst switches, all physical ports are assigned untrusted
servers, cameras, DMP, wireless access points, VoIP/video conferencing gateways, mode. The network administrator must explicitly enable the trust settings on the physical
etc). Even when these devices are network administrator maintained and secured, port where trusted or conditionally trusted endpoints are connected. The Catalyst
QoS policies must still be enforced to classify traffic and assign it to the appropriate switches can trust the ingress packets based on 802.1P (CoS-based), ToS (ip-prec-based)
queue to provide bandwidth assurance and proper treatment during network or DSCP (DHCP-based) values. Best practice is to deploy DSCP-based trust mode on all
congestion. the trusted and conditionally-trusted endpoints. This offers a higher level of classification
• Conditionally-Trusted—A single physical connection with one trusted endpoint and and marking granularity than other methods. The following sample DSCP-based trust
a indirect untrusted endpoint must be deployed as conditionally-trusted model. The configuration must be enabled on the access-switch ports connecting to trusted or
trusted endpoints are still managed by the network administrator, but it is possible conditionally-trusted endpoints.
Schools QoS Deployment Guide SBA

Access (Multilayer or Routed-Access) UnTrusted Port


As described earlier, the default trust mode is untrusted when globally enabling QoS
Trusted Port function. Without explicit trust configuration on Fas0/1 port, the following show command
cr24-2960-DO(config)#interface FastEthernet0/5 verifies current trust state and mode:
cr24-2960-DO(config-if)# description CONNECTED TO IPVS 2500 - CAMERA cr24-2960-DO#show mls qos interface f0/1
cr24-2960-DO(config-if)# mls qos trust dscp FastEthernet0/1
trust state: not trusted
cr24-2960-DO#show mls qos interface f0/5 trust mode: not trusted
FastEthernet0/5 trust enabled flag: ena
trust state: trust dscp COS override: dis
trust mode: trust dscp default COS: 0
trust enabled flag: ena DSCP Mutation Map: Default DSCP Mutation Map
COS override: dis Trust device: none
default COS: 0 qos mode: port-based
DSCP Mutation Map: Default DSCP Mutation Map
Implementing QoS Classification
Trust device: none
qos mode: port-based When creating QoS classification policies, the network administrator needs to consider
what applications are present at the access edge (in the ingress direction) and whether
Conditionally-Trusted Port these applications are sourced from trusted or untrusted endpoints. If PC endpoints are
secured and centrally administered, then endpoint PCs may be considered trusted
cr24-2960-DO(config)#interface FastEthernet0/3 endpoints. In most deployments, this is not the case, thus PCs are considered untrusted
cr24-2960-DO(config-if)# description CONNECTED TO PHONE endpoints for the remainder of this document.
cr24-2960-DO(config-if)# mls qos trust device cisco-phone Not every application class, as defined in the Cisco-modified RFC 4594-based model, is
cr24-2960-DO(config-if)# mls qos trust dscp present in the ingress direction at the access edge; therefore, it is not necessary to
provision the following application classes at the access-layer:
cr24-2960-DO#show mls qos interface f0/3 • Network Control—It is assumed that access-layer switch will not transmit or receive
FastEthernet0/3 network control traffic from endpoints; hence this class is not implemented.
trust state: trust dscp • Broadcast Video —Broadcast video and multimedia streaming server are centrally
trust mode: trust dscp deployed at the district office and multicast traffic is originated from trusted data
trust enabled flag: ena center servers and is unidirectional to school site endpoints (and should not be
COS override: dis sourced from school endpoints).
default COS: 0 • Operation, Administration and Management—Primarily generated by network
DSCP Mutation Map: Default DSCP Mutation Map devices (routers, switches) and collected by management stations which are typically
Trust device: cisco-phone
deployed in the trusted data center network, or a network control center.
qos mode: port-based All applications present at the access edge need to be assigned a classification, as shown
in Figure 6. Voice traffic is primarily sourced from Cisco IP telephony devices residing in
the voice VLAN (VVLAN). These are trusted devices, or conditionally trusted, if users also
attach PC's, etc to the same port. Voice communication may also be sourced from PC's
with soft-phone applications, like Cisco Unified Personal Communicator (CUPC). Since
such applications share the same UDP port range as multimedia conferencing traffic
(UDP/RTP ports 16384-32767) this soft-phone VoIP traffic is indistinguishable, and
should be classified with multimedia conferencing streams.
Schools QoS Deployment Guide SBA

Figure 6 QoS Classes cr24-3560r-DO(config-ext-nacl)# permit udp any any eq 1526


cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 1575
Present at Campus Trust
Application PHB Application Examples cr24-3560r-DO(config-ext-nacl)# permit udp any any eq 1575
Access-Edge (Ingress)? Boundary
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 1630
Network Control CS6 EIGRP, OSPF, HSRP, IKE
cr24-3560r-DO(config-ext-nacl)#
VoIP EF Cisco IP Phone Yes Trusted cr24-3560r-DO(config-ext-nacl)#ip access-list extended BULK-DATA
Broadcast Video Cisco IPVS, Enterprise TV
cr24-3560r-DO(config-ext-nacl)# remark FTP
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq ftp
Realtime Interactive CS4 Cisco TelePresence Yes Trusted
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq ftp-data
Multimedia Conferencing AF4 Cisco CUPC, WebEx Yes Untrusted cr24-3560r-DO(config-ext-nacl)# remark SSH/SFTP
Multimedia Streaming AF3 Cisco DMS, IP/TV cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 22
cr24-3560r-DO(config-ext-nacl)# remark SMTP/SECURE SMTP
Signaling CS3 SCCP, SIP, H.323 Yes Trusted
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq smtp
Transactional Data AF2 ERP Apps, CRM Apps Yes Untrusted cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 465
OAM CS2 SNMP, SSH, Syslog cr24-3560r-DO(config-ext-nacl)# remark IMAP/SECURE IMAP
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 143
Bulk Data AF1 Email, FTP, Backup Yes Untrusted
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 993
Best Effort DF Default Class Yes Untrusted
cr24-3560r-DO(config-ext-nacl)# remark POP3/SECURE POP3

227562
Scavenger CS1 YouTube, Gaming, P2P Yes Untrusted cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq pop3
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 995
cr24-3560r-DO(config-ext-nacl)# remark CONNECTED PC BACKUP
MQC offers scalability and flexibility in configuring QoS to classify all 8 application cr24-3560r-DO(config-ext-nacl)# permit tcp any eq 1914 any
classes by using match statements or an extended access-list to match the exact value or
cr24-3560r-DO(config-ext-nacl)#
range of Layer-4 known ports that each application uses to communicate on the network.
The following sample configuration creates an extended access-list for each application cr24-3560r-DO(config-ext-nacl)#ip access-list extended DEFAULT
and then applies it under class-map configuration mode. cr24-3560r-DO(config-ext-nacl)# remark EXPLICIT CLASS-DEFAULT
cr24-3560r-DO(config-ext-nacl)# permit ip any any
cr24-3560r-DO(config)#ip access-list extended MULTIMEDIA-CONFERENCING cr24-3560r-DO(config-ext-nacl)#
cr24-3560r-DO(config-ext-nacl)# remark RTP cr24-3560r-DO(config-ext-nacl)#ip access-list extended SCAVENGER
cr24-3560r-DO(config-ext-nacl)# permit udp any any range 16384 32767 cr24-3560r-DO(config-ext-nacl)# remark KAZAA
cr24-3560r-DO(config-ext-nacl)#! cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 1214
cr24-3560r-DO(config-ext-nacl)#ip access-list extended SIGNALING cr24-3560r-DO(config-ext-nacl)# permit udp any any eq 1214
cr24-3560r-DO(config-ext-nacl)# remark SCCP cr24-3560r-DO(config-ext-nacl)# remark MICROSOFT DIRECT X GAMING
cr24-3560r-DO(config-ext-nacl)# permit tcp any any range 2000 2002 cr24-3560r-DO(config-ext-nacl)# permit tcp any any range 2300 2400
cr24-3560r-DO(config-ext-nacl)# remark SIP cr24-3560r-DO(config-ext-nacl)# permit udp any any range 2300 2400
cr24-3560r-DO(config-ext-nacl)# permit tcp any any range 5060 5061 cr24-3560r-DO(config-ext-nacl)# remark APPLE ITUNES MUSIC SHARING
cr24-3560r-DO(config-ext-nacl)# permit udp any any range 5060 5061 cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 3689
cr24-3560r-DO(config-ext-nacl)# cr24-3560r-DO(config-ext-nacl)# permit udp any any eq 3689
cr24-3560r-DO(config-ext-nacl)#ip access-list extended TRANSACTIONAL-DATA cr24-3560r-DO(config-ext-nacl)# remark BITTORRENT
cr24-3560r-DO(config-ext-nacl)# remark HTTPS cr24-3560r-DO(config-ext-nacl)# permit tcp any any range 6881 6999
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 443 cr24-3560r-DO(config-ext-nacl)# remark YAHOO GAMES
cr24-3560r-DO(config-ext-nacl)# remark ORACLE-SQL*NET cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 11999
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 1521 cr24-3560r-DO(config-ext-nacl)# remark MSN GAMING ZONE
cr24-3560r-DO(config-ext-nacl)# permit udp any any eq 1521 cr24-3560r-DO(config-ext-nacl)# permit tcp any any range 28800 29100
cr24-3560r-DO(config-ext-nacl)# remark ORACLE cr24-3560r-DO(config-ext-nacl)#
cr24-3560r-DO(config-ext-nacl)# permit tcp any any eq 1526
Schools QoS Deployment Guide SBA

Creating class-map for each application services and applying match statement:
Table 1
cr24-3560r-DO(config)#class-map match-all VVLAN-SIGNALING
Application Policing Rate Conform-Action Exceed-Action
cr24-3560r-DO(config-cmap)# match ip dscp cs3
VoIP Signaling <32 kbps Pass Drop
cr24-3560r-DO(config-cmap)#
cr24-3560r-DO(config-cmap)#class-map match-all VVLAN-VOIP VoIP Bearer <128 kbps Pass Drop

cr24-3560r-DO(config-cmap)# match ip dscp ef Multimedia Conferencing <5Mbps1 Pass Drop


cr24-3560r-DO(config-cmap)# Signaling <32 kbps Pass Drop
cr24-3560r-DO(config-cmap)#class-map match-all MULTIMEDIA-CONFERENCING 1
Transactional Data <10 Mbps Pass Remark to CS1
cr24-3560r-DO(config-cmap)# match access-group name Bulk Data <10 Mbps 1 Pass Remark to CS1
MULTIMEDIA-CONFERENCING 1
Best Effort <10 Mbps Pass Remark to CS1
cr24-3560r-DO(config-cmap)#
Scavenger <10 Mbps 1 Pass Drop
cr24-3560r-DO(config-cmap)#class-map match-all SIGNALING
cr24-3560r-DO(config-cmap)# match access-group name SIGNALING 1. Rate varies based on several factors as defined earlier. This table depicts sample rate-limiting
cr24-3560r-DO(config-cmap)# values.
cr24-3560r-DO(config-cmap)#class-map match-all TRANSACTIONAL-DATA
cr24-3560r-DO(config-cmap)# match access-group name TRANSACTIONAL-DATA As described in the “QoS in Catalyst Fixed Configuration Switches” section on page -1, the
cr24-3560r-DO(config-cmap)# policer capabilities differ in Catalyst switching platforms. When deploying policer policies
cr24-3560r-DO(config-cmap)#class-map match-all BULK-DATA on the access-layer switches the following platform limitations must be taken into
cr24-3560r-DO(config-cmap)# match access-group name BULK-DATA consideration:
cr24-3560r-DO(config-cmap)# • The Catalyst 2960 and 2975 can only police to a minimum rate of 1 Mbps; all other
cr24-3560r-DO(config-cmap)#class-map match-all DEFAULT platforms within this switch-product family can police to a minimum rate of 8 kbps.
cr24-3560r-DO(config-cmap)# match access-group name DEFAULT • Only the Cisco Catalyst 3650-E and 3750-E support policing on 10 Gigabit Ethernet
cr24-3560r-DO(config-cmap)# interfaces.
cr24-3560r-DO(config-cmap)#class-map match-all SCAVENGER The following sample configuration shows how to deploy policing for multiple classes on
cr24-3560r-DO(config-cmap)# match access-group name SCAVENGER trusted and conditionally-trusted ingress ports in access-layer switches.

Trusted or Conditionally-Trusted Port


Implementing Ingress Policer cr24-3560r-DO(config)#policy-map Phone+PC-Policy
It is important to limit how much bandwidth each class may use at the ingress to the cr24-3560r-DO(config-pmap)# class VVLAN-VOIP
access-layer for two primary reasons: cr24-3560r-DO(config-pmap-c)# police 128000 8000 exceed-action drop
• Bandwidth Bottleneck—To prevent network congestion, each physical port at trust cr24-3560r-DO(config-pmap-c)# class VVLAN-SIGNALING
boundary must be rate-limited. The rate-limit value may differ based on several cr24-3560r-DO(config-pmap-c)# police 32000 8000 exceed-action drop
factors—end-to-end network bandwidth capacity, end-station and application cr24-3560r-DO(config-pmap-c)# class MULTIMEDIA-CONFERENCING
performance capacities, etc. cr24-3560r-DO(config-pmap-c)# police 5000000 8000 exceed-action drop
• Bandwidth Security—Well-known applications like Cisco IP telephony, use a fixed cr24-3560r-DO(config-pmap-c)# class SIGNALING
amount of bandwidth per device, based on codec. It is important to police cr24-3560r-DO(config-pmap-c)# police 32000 8000 exceed-action drop
high-priority application traffic which is assigned to the high-priority queue, cr24-3560r-DO(config-pmap-c)# class TRANSACTIONAL-DATA
otherwise it could consume too much overall network bandwidth and impact other
cr24-3560r-DO(config-pmap-c)# police 10000000 8000 exceed-action
application performance.
policed-dscp-transmit
In addition to policing, the rate-limit function also provides the ability to take different cr24-3560r-DO(config-pmap-c)# class BULK-DATA
actions on the excess incoming traffic which exceeds the established limits. The
cr24-3560r-DO(config-pmap-c)# police 10000000 8000 exceed-action
exceed-action for each class must be carefully designed based on the nature of
policed-dscp-transmit
application to provide best effort service based on network bandwidth availability. Table
cr24-3560r-DO(config-pmap-c)# class SCAVENGER
10 provides best practice policing guidelines for different classes to be implemented for
trusted and conditional-trusted endpoints at the network edge. cr24-3560r-DO(config-pmap-c)# police 10000000 8000 exceed-action drop
cr24-3560r-DO(config-pmap-c)# class DEFAULT
Schools QoS Deployment Guide SBA

cr24-3560r-DO(config-pmap-c)# police 10000000 8000 exceed-action All ingress traffic (default class) from an untrusted endpoint must be marked without a
policed-dscp-transmit explicit classification. The following sample configuration shows how to implement explicit
DSCP marking:
All ingress traffic (default class) from untrusted endpoint be must be policed without
explicit classification that requires differentiated services. The following sample Untrusted Port
configuration shows how to deploy policing on untrusted ingress ports in access-layer cr24-3560r-DO(config)#policy-map UnTrusted-PC-Policy
switches:
cr24-3560r-DO(config-pmap)# class class-default
cr24-3560r-DO(config-pmap-c)# set dscp default
UnTrusted Port
cr24-3560r-DO(config)#policy-map UnTrusted-PC-Policy Applying Ingress Policies
cr24-3560r-DO(config-pmap)# class class-default
the access-layer to enforce the QoS configuration. Cisco Catalyst switches offer three
cr24-3560r-DO(config-pmap-c)# police 10000000 8000 exceed-action drop
simplified methods to apply service-policies. Depending on the deployment model, any
of these methods may be used:
Implementing Ingress Marking
• Port-based QoS—Applying service-policy on a per physical port basis will force
Accurate DSCP marking of ingress traffic at the access-layer switch is critical to ensure traffic to pass-through the QoS policies before entering the network. Port-based QoS
proper QoS service treatment as traffic traverses through the network. All classified and functions on a per-physical port basis even if the port is associated with a logical
policed traffic must be explicitly marked using the policy-map configuration based on an VLAN.
8-class QoS model as shown in Figure 6.
• VLAN-based QoS—Applying service-policy on per VLAN basis requires the
Best practice is to use a explicit marking command (set dscp) even for trusted application policy-map to be attached to a logical Layer-3 SVI interface. Every physical port
classes (like VVLAN-VOIP and VVLAN-SIGNALING), rather than a trust policy-map action. associated with the VLAN will require an extra configuration to enforce the QoS
A trust statement in a policy map requires multiple hardware entries, while the use of an policies defined on a logical interface.
explicit (seemingly redundant) marking command, improves the hardware efficiency.
• Per-Port/Per-VLAN-based QoS—Not supported on all the Catalyst platforms and
The following sample configuration shows how to implement explicit marking for multiple the configuration commands are platform-specific. Per-port/per-VLAN-based QoS
classes on trusted and conditionally-trusted ingress ports in access-layer switches: creates a nested hierarchical policy-map that operates on a trunk interface. A
different policy-map can be applied on each logical SVI interface that is associated
Trusted or Conditionally-Trusted Port to a single physical port.
cr24-3560r-DO(config)#policy-map Phone+PC-Policy Figure 7 Depicts All Three QoS Implementation Method
cr24-3560r-DO(config-pmap)# class VVLAN-VOIP
Port-Based QoS VLAN-Based QoS Per-Port/ Per-VLAN Based QoS
cr24-3560r-DO(config-pmap-c)# set dscp ef
VLAN Interface VLAN Interface VLAN Interface
cr24-3560r-DO(config-pmap-c)# class VVLAN-SIGNALING
VVLAN 10 VVLAN 20
VLAN 10 VLAN 20 VLAN 10 VLAN 20
cr24-3560r-DO(config-pmap-c)# set dscp cs3 DVLAN 100 DVLAN 200
cr24-3560r-DO(config-pmap-c)# class MULTIMEDIA-CONFERENCING
Physical Ports
cr24-3560r-DO(config-pmap-c)# set dscp af41

227563
cr24-3560r-DO(config-pmap-c)# class SIGNALING Physical port attached Single Logical port attached Multiple Logical ports attached
with single service-policy with single service-policy with different service-policy
cr24-3560r-DO(config-pmap-c)# set dscp cs3
cr24-3560r-DO(config-pmap-c)# class TRANSACTIONAL-DATA
The following sample configuration shows how to deploy port-based QoS on the
access-layer switches:
cr24-3560r-DO(config-pmap-c)# set dscp af21
cr24-3560r-DO(config-pmap-c)# class BULK-DATA
cr24-3560r-DO(config)#interface fastethernet0/4
cr24-3560r-DO(config-pmap-c)# set dscp af11
cr24-3560r-DO(config-if)# description CONNECTED TO PHONE+PC
cr24-3560r-DO(config-pmap-c)# class SCAVENGER
cr24-3560r-DO(config-if)# service-policy input Phone+PC-Policy
cr24-3560r-DO(config-pmap-c)# set dscp cs1
cr24-3560r-DO(config-pmap-c)# class DEFAULT
cr24-3560r-DO#show policy-map interface f0/4 | inc Service|Class
cr24-3560r-DO(config-pmap-c)# set dscp default
Service-policy input: Phone+PC-Policy
Class-map: VVLAN-VOIP (match-all)
Class-map: VVLAN-SIGNALING (match-all)
Class-map: MULTIMEDIA-CONFERENCING (match-all)
Schools QoS Deployment Guide SBA

Class-map: SIGNALING (match-all) The DSCP marked packets in the policy-map must be assigned to the appropriate queue
Class-map: TRANSACTIONAL-DATA (match-all) and each queue must be configured with the recommended WTD threshold as defined
Class-map: BULK-DATA (match-all) in Figure 8. The following ingress queue configuration must be enabled in global
Class-map: SCAVENGER (match-all) configuration mode on every access-layer switch.
cr25-3750-DO(config)#mls qos srr-queue input priority-queue 2 bandwidth 30
Class-map: DEFAULT (match-all) ! Q2 is enabled as a strict-priority ingress queue with 30% BW
Class-map: class-default (match-any)
cr25-3750-DO(config)#mls qos srr-queue input bandwidth 70 30
! Q1 is assigned 70% BW via SRR shared weights
Applying Ingress Queueing ! Q1 SRR shared weight is ignored (as it has been configured as a PQ)

Fixed configuration Cisco Catalyst switches (29xx and 3xxx) not only offer differentiated cr25-3750-DO(config)#mls qos srr-queue input threshold 1 80 90
! Q1 thresholds are configured at 80% (Q1T1) and 90% (Q1T2)
services on the network ports but also internally on the switching fabric. After enabling ! Q1T3 is implicitly set at 100% (the tail of the queue)
QoS and attaching inbound policies on the physical ports, all the packets that meet the ! Q2 thresholds are all set (by default) to 100% (the tail of Q2)
specified policy are forwarded to the switching fabric for egress switching. The aggregate ! This section configures ingress DSCP-to-Queue Mappings
bandwidth from all edge ports may exceed switching fabric bandwidth and cause internal cr25-3750-DO(config)# mls qos srr-queue input dscp-map queue 1 threshold 1 0 8 10 12 14
congestion. ! DSCP DF, CS1 and AF1 are mapped to ingress Q1T1
cr25-3750-DO(config)# mls qos srr-queue input dscp-map queue 1 threshold 1 16 18 20 22
These platforms support two internal ingress queues: normal queue and priority queue. ! DSCP CS2 and AF2 are mapped to ingress Q1T1
cr25-3750-DO(config)# mls qos srr-queue input dscp-map queue 1 threshold 1 26 28 30 34 36
The ingress queue inspects the DSCP value on each incoming frame and assigns it to 38
either the normal or priority queue. High priority traffic, like DSCP EF marked packets, are ! DSCP AF3 and AF4 are mapped to ingress Q1T1
placed in the priority queue and switched before processing the normal queue. cr25-3750-DO(config)#mls qos srr-queue input dscp-map queue 1 threshold 2 24
! DSCP CS3 is mapped to ingress Q1T2
The Catalyst 3750-E family of switches supports the weighted tail drop (WTD) congestion cr25-3750-DO(config)#mls qos srr-queue input dscp-map queue 1 threshold 3 48 56
! DSCP CS6 and CS7 are mapped to ingress Q1T3 (the tail of Q1)
avoidance mechanism. WTD is implemented on queues to manage the queue length. cr25-3750-DO(config)#mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46
WTD drops packets from the queue, based on dscp value, and the associated threshold. ! DSCP CS4, CS5 and EF are mapped to ingress Q2T3 (the tail of the PQ)
If the threshold is exceeded for a given internal DSCP value, the switch drops the packet.
cr25-3750-DO#show mls qos input-queue
Each queue has three threshold values. The internal DSCP determines which of the three Queue: 12
threshold values is applied to the frame. Two of the three thresholds are configurable -----------------------------------
buffers :9010
(explicit) and one is not (implicit). This last threshold corresponds to the tail of the queue bandwidth :7030
(100% limit). priority :030
threshold1:80100
Figure 8 depicts how different class-of-service applications are mapped to the Ingress threshold2:90100
Queue structure (1P1Q3T) and how each queue is assigned a different WTD threshold.
cr25-3750-DO#show mls qos maps dscp-input-q
Figure 8 Ingress Queueing Dscp-inputq-threshold map:
d1 :d2 0 1 2 3 4 5 6 7
8 9
Application PHB Ingress Queue
1P1Q3T
----------------------------------------------------------------------------------------
0 : 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01
Network Control CS7 EF 1 : 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01
Internetwork Control CS6 Queue 2 2 : 01-01 01-01 01-01 01-01 01-02 01-01 01-01 01-01 01-01 01-01
CS5
Priority-Queue 3 : 01-01 01-01 02-03 01-01 01-01 01-01 01-01 01-01 01-01 01-01
VoIP EF CS4 4 : 02-03 02-01 02-01 02-01 02-01 02-01 02-03 02-01 01-03 01-01
5 : 01-01 01-01 01-01 01-01 01-01 01-01 01-03 01-01 01-01 01-01
Broadcast Video CS5 CS7 Q1T3 6 : 01-01 01-01 01-01 01-01
Realtime Interactive CS4 CS6
Q1T2
Multimedia Conferencing AF4 CS3
Deploying Egress QoS
Q1T1
Multimedia Streaming AF3 AF4
The QoS implementation for egress traffic toward the network edge on access-layer
Signaling CS3 AF3 switches is much simpler than the ingress traffic QoS. The egress QoS implementation
Transactional Data AF2 AF2 Queue 1 provides optimal queueing policies for each class and sets the drop thresholds to prevent
Normal Queue
network congestion and application performance impact. Cisco Catalyst switches
OAM CS2 CS2
support four hardware queues which are assigned the following policies:
Bulk Data AF1 AF1
• Real-time queue (to support a RFC 3246 EF PHB service)
Best Effort DF DF
• Guaranteed bandwidth queue (to support RFC 2597 AF PHB services)
227564

Scavenger CS1 CS1


• Default queue (to support a RFC 2474 DF service)
Schools QoS Deployment Guide SBA

• Bandwidth constrained queue (to support a RFC 3662 scavenger service) Figure 10 Access-Layer 1P3Q3T Egress Queue model
As a best practice, each physical or logical link must diversify bandwidth assignment to
Egress Queue
map with hardware queues: Application PHB
1P3Q3T
• Real-time queue should not exceed 33% of the link's bandwidth.
Network Control CS7 CS1 Queue 4 Q4T2
• Default queue should be at least 25% of the link's bandwidth. AF1 (5%) Q4T1
Internetwork Control CS6
• Bulk/scavenger queue should not exceed 5% of the link's bandwidth.
DF Queue 3
Figure 9 shows the best practice egress queue bandwidth allocation for each class. VoIP EF (55%)

Broadcast Video CS5 CS7 Q2T3


Figure 9 Engress QoS
Realtime Interactive CS4 CS6 Queue
5% Multimedia Conferencing AF4 CS3 2 Q2T2

Multimedia Streaming AF3 CS2 Q2T1


33% Real-Time (30%)
25% Signaling CS3
AF4
Guaranteed
Transactional Data AF2
AF3
Best-Effort OAM CS2
AF2
Scavenger/Bulk Bulk Data AF1 EF
Queue 1
Best Effort DF CS5 Priority-Queue
227565

37% (30%)

227566
Scavenger CS1 CS4

Given these minimum queuing requirements and bandwidth allocation


recommendations, the following application classes can be mapped to the respective DSCP marked packets are assigned to the appropriate queue and each queue is
queues: configured with appropriate WTD threshold as defined in Figure 10. Egress queueing is
the same on network edge port as well as on uplink connected to internal network, and it
• Realtime Queue—Voice, broadcast video, and realtime interactive may be mapped is independent of trust mode. The following egress queue configuration in global
to the realtime queue (per RFC 4594).
configuration mode, must be enabled on every access-layer switch in the network.
• Guaranteed Queue—Network/internetwork control, signaling, network management, ! This section configures explicit WTD thresholds on Q2 and Q4
multimedia conferencing, multimedia streaming, and transactional data can be cr25-3750-DO(config)#mls qos queue-set output 1 threshold 2 80 90 100 100
mapped to the guaranteed bandwidth queue. Congestion avoidance mechanisms ! Q2T1 is set to 80%; Q2T2 is set to 90%
cr25-3750-DO(config)#mls qos queue-set output 1 threshold 4 60 100 100 100
(i.e., selective dropping tools), such as WRED, can be enabled on this class. If ! Q4T1 is set to 60%; all other thresholds for Q4 remain at 100%
configurable drop thresholds are supported on the platform, these may be enabled
to provide intra-queue QoS to these application classes, in the respective order they ! This section configures egress DSCP-to-Queue mappings
are listed (such that control plane protocols receive the highest level of QoS within a cr25-3750-DO(config)# mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46
given queue). ! DSCP CS4, CS5 and EF are mapped to egress Q1T3 (tail of the PQ)
cr25-3750-DO(config)# mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20 22
• Scavenger/Bulk Queue—Bulk data and scavenger traffic can be mapped to the ! DSCP CS2 and AF2 are mapped to egress Q2T1
bandwidth-constrained queue and congestion avoidance mechanisms can be cr25-3750-DO(config)# mls qos srr-queue output dscp-map queue 2 threshold 1 26 28 30 34 36
enabled on this class. If configurable drop thresholds are supported on the platform, 38
these may be enabled to provide inter-queue QoS to drop scavenger traffic ahead of ! DSCP AF3 and AF4 are mapped to egress Q2T1
cr25-3750-DO(config)#mls qos srr-queue output dscp-map queue 2 threshold 2 24
bulk data. ! DSCP CS3 is mapped to egress Q2T2
cr25-3750-DO(config)#mls qos srr-queue output dscp-map queue 2 threshold 3 48 56
• Default Queue—Best effort traffic can be mapped to the default queue; congestion ! DSCP CS6 and CS7 are mapped to egress Q2T3
avoidance mechanisms can be enabled on this class. cr25-3750-DO(config)#mls qos srr-queue output dscp-map queue 3 threshold 3 0
! DSCP DF is mapped to egress Q3T3 (tail of the best effort queue)
The egress queueing is designed to map traffic, based on DSCP value, to four egress cr25-3750-DO(config)#mls qos srr-queue output dscp-map queue 4 threshold 1 8
queues. as shown above. The egress QoS model for a platform that supports ! DSCP CS1 is mapped to egress Q4T1
DSCP-to-queue mapping with a 1P3Q8T queuing structure is depicted in Figure 10. cr25-3750-DO(config)# mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14
! DSCP AF1 is mapped to Q4T2 (tail of the less-than-best-effort queue)

! This section configures interface egress queuing parameters


cr25-3750-DO(config)#interface range GigabitEthernet1/0/1-48
cr25-3750-DO(config-if-range)# queue-set 1
! The interface(s) is assigned to queue-set 1
Schools QoS Deployment Guide SBA

cr25-3750-DO(config-if-range)# srr-queue bandwidth share 1 30 35 5 Table 3 Summarized Network Edge Egress QoS Deployment Guidelines (continued)
! The SRR sharing weights are set to allocate 30% BW to Q2
! 35% BW to Q3 and 5% BW to Q4
! Q1 SRR sharing weight is ignored, as it will be configured as a PQ
Classification / Bandwidt
cr25-3750-DO(config-if-range)# priority-queue out Trust Marking / Egress h
! Q1 is enabled as a strict priority queue End-Point Model Policing Queueing Share
cr25-3750-DO#show mls qos interface GigabitEthernet1/0/27 queueing Phone + Mobile PC Conditionally-Truste None Yes Yes
GigabitEthernet1/0/27 d
Egress Priority Queue : enabled
Shaped queue weights (absolute) : 25 0 0 0
Shared queue weights : 1 30 35 5 IP Video surveillance Trusted None Yes Yes
The port bandwidth limit : 100 (Operational Bandwidth:100.0) Camera
The port is mapped to qset : 1

Table 2 and Table 3 summarize the ingress and egress QoS policies at the access-layer
for several types of validated endpoints. Digital Media Player Trusted None Yes Yes

Table 2 Summarized Network Edge Ingress QoS Deployment Guidelines Core facing Uplinks Trusted None Yes Yes

Ingres
s Deploying Network Core QoS
Trust Classifica Queuei
End-Point Model DSCP Trust tion Marking Policing ng All connections between internal network devices that are deployed within the network
domain boundary are classified as trusted devices and follow the same QoS best
Unmanaged UnTrusted Don’t Trust. None None Yes Yes practices recommended in the previous section. Ingress and egress core QoS policies
devices, printers Default.
etc
are simpler than those applied at the network edge, See Figure 11.
Managed Trusted Trust 8 Class Yes Yes Yes Figure 11 Core QoS
secured devices, Model
Servers etc
Phone Trusted Trust Yes Yes Yes Yes
Phone + Mobile Conditionally-Tr Trust Yes Yes Yes Yes
PC usted
IP Video Trusted Trust No No No Yes Distribution/Core
surveillance
Camera
Digital Media Trusted Trust No No No Yes
Player
Core facing Trusted Trust No No No Yes
Uplinks
Access

227567
Ingress QoS Ploicy Egress QoS Ploicy
Table 3 Summarized Network Edge Egress QoS Deployment Guidelines

Classification / Bandwidt
The core network devices are considered trusted and rely on the access-switch to
Trust Marking / Egress h properly mark DSCP values. The core network is deployed to ensure consistent
End-Point Model Policing Queueing Share differentiated QoS service across the network. This ensures there is no service quality
degradation for high-priority traffic, such as IP telephony or video.
Unmanaged devices, UnTrusted None Yes Yes
printers etc The QoS implementation at the District Office and Larger School Site differ from the
Smaller School Site, due to different platforms used as the collapsed core router (Catalyst
4500 vs Catalyst 3750 StackWise).
Managed secured devices, Trusted None Yes Yes
Servers etc

Phone Trusted None Yes Yes


Schools QoS Deployment Guide SBA

Deploying District Office or Large School Site Ingress QoS cr36-3750s-SS100(config)#mls qos
! Enables QoS function in the switch
The District Office collapsed core is deployed with Cisco Catalyst 4500 with
Supervisor-6E, whereas the Larger School Site collapsed core is deployed with Cisco
Catalyst 4500 with either Supervisor-6E or Supervisor-V. The Supervisor-6E product has cr36-3750s-SS100#show mls qos
a redesigned QoS implementation which matches Cisco IOS routers. No ingress QoS QoS is enabled
configuration is required, since QoS is enabled by default, and all ports are considered QoS ip packet dscp rewrite is enabled
trusted.
The Cisco Catalyst 4500 with Supervisor-V requires ingress QoS configuration similar to After QoS is globally enabled, all interfaces are in the untrusted mode by default. QoS
trusted endpoints in the access-layer. trust settings must be set on each Layer 2 or Layer 3 port that is physically connected to
Following is a sample configuration which enables QoS in the Catalyst 4500 with another device within the network trust boundary. When Cisco Catalyst 3750-E StackWise
Supervisor-V Plus is deployed in EtherChannel mode, the QoS trust settings must be applied to every
cr35-4507-SS1(config)#qos
physical member-link. Best practice is to enable trust DSCP settings on each physical and
logical interface that connects to another internal trusted device (e.g., access-layer
! Enables QoS function in the switch
switches in wiring closet or data-center, a router, wireless LAN controller (WLC)).
cr36-3750s-SS100(config)#int range gi1/0/49 , gi3/0/49
cr35-4507-SS1#show qos
cr36-3750s-SS100(config-if-range)# description Connected to
QoS is enabled globally cr36-2960-SS100
IP header DSCP rewrite is enabled cr36-3750s-SS100(config-if-range)#mls qos trust dscp

After QoS is globally enabled, all interfaces are in the untrusted mode by default. QoS cr36-3750s-SS100#show mls qos interface Gi1/0/49
trust settings must be set on each Layer 2 or Layer 3 port that is physically connected to GigabitEthernet1/0/49
another device within the network trust boundary. When Cisco Catalyst 4500 is deployed
trust state: trust dscp
in EtherChannel mode, the QoS trust settings must be applied to every physical
member-link and logical port-channel interface. Best practice is to enable trust DSCP trust mode: trust dscp
settings on each physical and logical interface that connects to another internal trusted trust enabled flag: ena
device (e.g., access-layer switches in wiring closet or data-center, a router, wireless LAN COS override: dis
controller (WLC)). default COS: 0
cr35-4507-SS1(config)#interface range Po11 , Gi1/2 , Gi2/2 DSCP Mutation Map: Default DSCP Mutation Map
cr35-4507-SS1(config-if-range)#description Connected to cr35-2960-SS1
Trust device: none
cr35-4507-SS1(config-if-range)#qos trust dscp
qos mode: port-based
cr35-4507-SS1#show qos interface Port-channel 11
QoS is enabled globally
Port QoS is enabled
Additional ingress QoS techniques (such as classification, marking, and policing) are not
Administrative Port Trust State: 'dscp' required at the collapsed core layer since these functions are already performed by the
Operational Port Trust State: 'dscp' access-layer switches. The ingress queueing and DSCP-Ingress-Queue function in
Trust device: none 3750-E StackWise Plus must be enabled to allow differentiation between normal versus
Default DSCP: 0 Default CoS: 0 high-priority traffic. The ingress queuing configuration is consistent with the
implementation at the access-edge. Following is a sample configuration for the ingress
Additional ingress QoS techniques (such as classification, marking, and policing) are not queues of the Catalyst 3750-E StackWise collapsed core switch:
required at the collapsed core layer since these functions are already performed by the cr36-3750-SS100(config)#mls qos srr-queue input priority-queue 2 bandwidth 30
access-layer switches. The architecture of Catalyst 4500 with classic or next-generation ! Q2 is enabled as a strict-priority ingress queue with 30% BW
Supervisor do not need ingress queueing since all of the forwarding decisions are made cr36-3750-SS100(config)#mls qos srr-queue input bandwidth 70 30
centrally on the supervisor. There are no additional QoS configurations required at the ! Q1 is assigned 70% BW via SRR shared weights
collapsed core-layer system. ! Q1 SRR shared weight is ignored (as it has been configured as a PQ)

cr36-3750-SS100(config)#mls qos srr-queue input threshold 1 80 90


Deploying Small School Site Ingress QoS ! Q1 thresholds are configured at 80% (Q1T1) and 90% (Q1T2)
! Q1T3 is implicitly set at 100% (the tail of the queue)
The Smaller School Site is deployed using Cisco Catalyst 3750-E StackWise as the ! Q2 thresholds are all set (by default) to 100% (the tail of Q2)
collapsed core switch. The QoS implementation remains the same whether deployed as ! This section configures ingress DSCP-to-Queue Mappings
3750-E StackWise or as a standalone switch. By default, QoS is disabled on the 3750-E cr36-3750-SS100(config)# mls qos srr-queue input dscp-map queue 1 threshold 1 0 8 10 12 14
switch. Following is a sample configuration to enable QoS in global configuration mode: ! DSCP DF, CS1 and AF1 are mapped to ingress Q1T1cr36-3750-SS100(config)# mls qos
srr-queue input dscp-map queue 1 threshold 1 16 18 20 22
Schools QoS Deployment Guide SBA

! DSCP CS2 and AF2 are mapped to ingress Q1T1 Figure 12 District Office School Network
cr36-3750-SS100(config)# mls qos srr-queue input dscp-map queue 1 threshold 1 26 28 30 34
36 38
! DSCP AF3 and AF4 are mapped to ingress Q1T1 Egress Queue
Application PHB
cr36-3750-SS100(config)#mls qos srr-queue input dscp-map queue 1 threshold 2 24 1P7Q1T (+DBL)
! DSCP CS3 is mapped to ingress Q1T2
cr36-3750-SS100(config)# mls qos srr-queue input dscp-map queue 1 threshold 3 48 56 Network Control CS7 EF
! DSCP CS6 and CS7 are mapped to ingress Q1T3 (the tail of Q1)
cr36-3750-SS100(config)# mls qos srr-queue input dscp-map queue 2 threshold 3 32 40 46
! DSCP CS4, CS5 and EF are mapped to ingress Q2T3 (the tail of the PQ) Internetwork Control CS6 CS5 Priority-Queue
(30%)
cr36-3750s-SS100#show mls qos input-queue VoIP EF CS4
Queue : 1 2
------------------------------------- Broadcast Video CS5 CS7 & CS6
buffers : 90 10 Q7 (10%)
CS3 & CS2
bandwidth : 70 30 Realtime Interactive CS4
priority : 0 30
threshold1: 80 100 AF4 Q6 (10%)
Multimedia Conferencing AF4
threshold2: 90 100

cr36-3750s-SS100#show mls qos maps dscp-input-q Multimedia Streaming AF3


Dscp-inputq-threshold map: AF3 Q5 (10%)
d1 :d2 0 1 2 3 4 5 6 7 Signaling CS3
8 9
Transactional Data AF2 AF2 Q4 (10%)
----------------------------------------------------------------------------------------
OAM CS2
0 : 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01
1 : 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 01-01 AF1 Q3 (4%)
2 : 01-01 01-01 01-01 01-01 01-02 01-01 01-01 01-01 01-01 01-01
Bulk Data AF1
3 : 01-01 01-01 02-03 01-01 01-01 01-01 01-01 01-01 01-01 01-01
4 : 02-03 02-01 02-01 02-01 02-01 02-01 02-03 02-01 01-03 01-01 Best Effort DF DF Q2 (1%)

227568
5 : 01-01 01-01 01-01 01-01 01-01 01-01 01-03 01-01 01-01 01-01
6 : 01-01 01-01 01-01 01-01 Scavenger CS1 CS1 Q1 (25%)

Deploying District Office Egress QoS Implementing QoS policies on Sup-6E-based Catalyst 4500 platform follows IOS
(MQC)-model. The egress QoS implementation bundles the queueing and policing
The District Office is deployed with Cisco Catalyst 4500 with Supervisor-6E as the
functions on EtherChannel based networks. To provide low-latency for high priority traffic,
collapsed core router. Egress QoS from the collapsed core router provides optimized all lower priority traffic must wait until the priority-queue is empty. Best practice includes
queueing and drop thresholds to drop excess low-priority traffic and protect high-priority
implementing a policer along with the priority-queue to provide more fair treatment for all
traffic. traffic.
The Supervisor-6E supports up to 8 traffic classes for QoS mapping. It also supports a
The following sample configuration shows how to create an 8-class egress queueing
platform-specific congestion avoidance algorithm to provide Active Queue Management model and protect from high-priority traffic consuming more bandwidth than global
(AQM) with Dynamic Buffer Limiting (DBL). DBL tracks the queue length for each traffic flow
policies allow. The egress QoS service-policy must be applied to all the physical
in the switch. When the queue length of a flow exceeds its limit, DBL drops packets or sets EtherChannel member-links connected to different service-blocks (i.e., WAN edge, data
the Explicit Congestion Notification (ECN) bit in the TCP packet header. With 8 egress
center, access-layer switches, etc).
(1P7Q1T) queues and DBL capability in the Sup-6E, the bandwidth distribution for each
! Creating class-map for each classes using match dscp statement as marked by edge
class changes, as shown in Figure 12 systems
cr24-4507-DO(config)#class-map match-all PRIORITY-QUEUE
cr24-4507-DO(config-cmap)# match dscp ef
cr24-4507-DO(config-cmap)# match dscp cs5
cr24-4507-DO(config-cmap)# match dscp cs4
cr24-4507-DO(config-cmap)# class-map match-all CONTROL-MGMT-QUEUE
cr24-4507-DO(config-cmap)# match dscp cs7
cr24-4507-DO(config-cmap)# match dscp cs6
cr24-4507-DO(config-cmap)# match dscp cs3
cr24-4507-DO(config-cmap)# match dscp cs2
cr24-4507-DO(config-cmap)# class-map match-all MULTIMEDIA-CONFERENCING-QUEUE
cr24-4507-DO(config-cmap)# match dscp af41 af42 af43
cr24-4507-DO(config-cmap)# class-map match-all MULTIMEDIA-STREAMING-QUEUE
cr24-4507-DO(config-cmap)# match dscp af31 af32 af33
cr24-4507-DO(config-cmap)# class-map match-all TRANSACTIONAL-DATA-QUEUE
cr24-4507-DO(config-cmap)# match dscp af21 af22 af23
Schools QoS Deployment Guide SBA

cr24-4507-DO(config-cmap)# class-map match-all BULK-DATA-QUEUE Deploying Large School Site Egress QoS
cr24-4507-DO(config-cmap)# match dscp af11 af12 af13
cr24-4507-DO(config-cmap)# class-map match-all SCAVENGER-QUEUE The large school site is deployed with Cisco Catalyst 4500 and either Supervisor-6E or
cr24-4507-DO(config-cmap)# match dscp cs1 Supervisor-V as the collapsed core router. If the larger school site network is deployed
with Sup-6E, then the configuration is the same as described in the previous section.
! Creating policy-map and configure queueing for class-of-service
cr24-4507-DO(config)#policy-map EGRESS-POLICY The QoS deployment and implementation guidelines differ when the Cisco Catalyst 4500
cr24-4507-DO(config-pmap)# class PRIORITY-QUEUE is deployed with the classic Supervisor-V module. The SupV supervisor can have up to
cr24-4507-DO(config-pmap-c)# priority four egress queues like the Cisco Catalyst 29xx and 35xx/37xx Series switches. Before
cr24-4507-DO(config-pmap-c)# class CONTROL-MGMT-QUEUE forwarding egress traffic, each packet must be internally classified and placed in the
cr24-4507-DO(config-pmap-c)# bandwidth remaining percent 10
cr24-4507-DO(config-pmap-c)# class MULTIMEDIA-CONFERENCING-QUEUE
appropriate egress-queue. Placing traffic into different class-of-service queues, will offer
cr24-4507-DO(config-pmap-c)# bandwidth remaining percent 10 traffic prioritization and guaranteed bandwidth to the network. The following sample
cr24-4507-DO(config-pmap-c)# class MULTIMEDIA-STREAMING-QUEUE configuration shows how to implement egress QoS on the Catalyst 4500 with
cr24-4507-DO(config-pmap-c)# bandwidth remaining percent 10 Supervisor-V:
cr24-4507-DO(config-pmap-c)# class TRANSACTIONAL-DATA-QUEUE
cr35-4507-SS1(config)#qos dbl
cr24-4507-DO(config-pmap-c)# bandwidth remaining percent 10
! DBL is globally enabled
cr24-4507-DO(config-pmap-c)# dbl
cr35-4507-SS1(config)#no qos dbl dscp-based 32
cr24-4507-DO(config-pmap-c)# class BULK-DATA-QUEUE
cr35-4507-SS1(config)#no qos dbl dscp-based 40
cr24-4507-DO(config-pmap-c)# bandwidth remaining percent 4
cr35-4507-SS1(config)#no qos dbl dscp-based 46
cr24-4507-DO(config-pmap-c)# dbl
! DBL is explicitly disabled on DSCP CS4, CS5 and EF
cr24-4507-DO(config-pmap-c)# class SCAVENGER-QUEUE
! as these DSCP values are assigned to the PQ
cr24-4507-DO(config-pmap-c)# bandwidth remaining percent 1
! and as such should never experience congestion avoidance drops
cr24-4507-DO(config-pmap-c)# class class-default
cr35-4507-SS1(config)#qos dbl exceed-action ecn
cr24-4507-DO(config-pmap-c)# bandwidth remaining percent 25
! DBL will mark IP ECN bits in the event of congestion
cr24-4507-DO(config-pmap-c)# dbl
! This section configures the DBL policy-map
! Attaching egress service-policy on all physical member-link ports
cr35-4507-SS1(config)#policy-map DBL
cr24-4507-DO(config)#int range Gi1/1 - 6 , Gi2/1 - 6
cr35-4507-SS1(config-pmap)# class class-default
cr24-4507-DO(config-if-range)# service-policy output EGRESS-POLICY
cr35-4507-SS1(config-pmap-c)# dbl
! DBL is enabled on all flows
EtherChannel is an aggregated logical bundle interface that does not perform queueing ! (with the exception of DSCP CS4, CS5 and EF)
and relies on individual member-links to queue egress traffic. The policer to rate-limit ! This section configures the DSCP-to-Queue mappings
priority class traffic must be implemented on EtherChannel and not on individual
member-links since it governs the aggregate egress traffic limits. The following additional
cr35-4507-SS1(config)#qos map dscp 8 10 12 14 to tx-queue 1
policy-map must be created to classify priority-queue class traffic and rate-limit the traffic
! DSCP CS1 and AF1 are mapped to Q1 (the less than best effort queue)
to 30% of egress link capacity: cr35-4507-SS1(config)#qos map dscp 0 to tx-queue 2
cr24-4507-DO(config)#class-map match-any PRIORITY-QUEUE ! DSCP DF is mapped to Q2 (the best effort/default queue)
cr24-4507-DO(config-cmap)# match dscp ef cr35-4507-SS1(config)#qos map dscp 32 40 46 to tx-queue 3
! DSCP CS4, CS5 and EF are mapped to Q3 (the PQ)
cr24-4507-DO(config-cmap)# match dscp cs5 cr35-4507-SS1(config)#qos map dscp 16 18 20 22 to tx-queue 4
cr24-4507-DO(config-cmap)# match dscp cs4 ! DSCP CS2 and AF2 are mapped to Q4 (guaranteed BW queue)
cr35-4507-SS1(config)#qos map dscp 24 26 28 30 to tx-queue 4
! DSCP CS3 and AF3 are mapped to Q4 (guaranteed BW queue)
cr24-4507-DO(config)#policy-map PQ-POLICER cr35-4507-SS1(config)#qos map dscp 34 36 38 to tx-queue 4
cr24-4507-DO(config-pmap)# class PRIORITY-QUEUE ! DSCP AF4 is mapped to Q4 (guaranteed BW queue)
cr24-4507-DO(config-pmap-c)# police cir 300 m conform-action transmit cr35-4507-SS1(config)#qos map dscp 48 56 to tx-queue 4
! DSCP CS6 and CS7 are mapped to Q4 (guaranteed BW queue)
exceed-action drop
! This section configures all the EtherChannel member-link for egress queuing
cr35-4507-SS1(config)#interface range Gig1/1 - 6 , Gig2/1 - 6
cr35-4507-SS1(config-if-range)# tx-queue 1
cr24-4507-DO(config)#interface range Port-Channel 1 , Port-channel 11 - cr35-4507-SS1(config-if-tx-queue)# bandwidth percent 5
17 ! Q1 (less than best effort queue) is assigned 5% BW
cr35-4507-SS1(config-if-tx-queue)# tx-queue 2
cr24-4507-DO(config-if-range)#service-policy output PQ-POLICER cr35-4507-SS1(config-if-tx-queue)# bandwidth percent 35
! Q2 (default/best effort queue) is assigned 35% BW
cr35-4507-SS1(config-if-tx-queue)# tx-queue 3
cr35-4507-SS1(config-if-tx-queue)# priority high
cr35-4507-SS1(config-if-tx-queue)# bandwidth percent 30
! Q3 is enabled as a PQ and assigned 30% BW
cr35-4507-SS1(config-if-tx-queue)# tx-queue 4
cr35-4507-SS1(config-if-tx-queue)# bandwidth percent 30
Schools QoS Deployment Guide SBA

! Q4 (guaranteed BW queue) is assigned 30% BW ! This section configures explicit WTD thresholds on Q2 and Q4
cr35-4507-SS1(config-if-range)# service-policy output DBL cr36-3750s-SS100(config)#mls qos queue-set output 1 threshold 2 80 90 100 100
! DBL policy-map is attached to the interface(s) ! Q2T1 is set to 80%; Q2T2 is set to 90%
cr36-3750s-SS100(config)#mls qos queue-set output 1 threshold 4 60 100 100 100
cr35-4507-SS1#show qos dbl ! Q4T1 is set to 60%; all other thresholds for Q4 remain at 100%
QOS is enabled globally
DBL is enabled globally on DSCP values: ! This section configures egress DSCP-to-Queue mappings
0-31,33-39,41-45,47-63 cr36-3750s-SS100(config)# mls qos srr-queue output dscp-map queue 1 threshold 3 32 40 46
DBL flow includes vlan ! DSCP CS4, CS5 and EF are mapped to egress Q1T3 (tail of the PQ)
DBL flow includes layer4-ports cr36-3750s-SS100(config)# mls qos srr-queue output dscp-map queue 2 threshold 1 16 18 20
DBL uses ecn to indicate congestion 22
DBL exceed-action probability: 15% ! DSCP CS2 and AF2 are mapped to egress Q2T1
DBL max credits: 15
DBL aggressive credit limit: 10
DBL aggressive buffer limit: 2 packets cr36-3750s-SS100(config)#mls qos srr-queue output dscp-map queue 2 threshold 1 26 28 30 34
36 38
! DSCP AF3 and AF4 are mapped to egress Q2T1
cr36-3750s-SS100(config)#mls qos srr-queue output dscp-map queue 2 threshold 2 24
cr35-4507-SS1#show qos maps dscp tx-queue ! DSCP CS3 is mapped to egress Q2T2
DSCP-TxQueue Mapping Table (dscp = d1d2) cr36-3750s-SS100(config)#mls qos srr-queue output dscp-map queue 2 threshold 3 48 56
d1 : d2 0 1 2 3 4 5 6 7 8 9 ! DSCP CS6 and CS7 are mapped to egress Q2T3
------------------------------------------------ cr36-3750s-SS100(config)#mls qos srr-queue output dscp-map queue 3 threshold 3 0
0 : 02 01 01 01 01 01 01 01 01 01 ! DSCP DF is mapped to egress Q3T3 (tail of the best effort queue)
1 : 01 01 01 01 01 01 04 02 04 02 cr36-3750s-SS100(config)#mls qos srr-queue output dscp-map queue 4 threshold 1 8
2 : 04 02 04 02 04 02 04 02 04 02 ! DSCP CS1 is mapped to egress Q4T1
3 : 04 02 03 03 04 03 04 03 04 03 cr36-3750s-SS100(config)# mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14
4 : 03 03 03 03 03 03 03 03 04 04 ! DSCP AF1 is mapped to Q4T2 (tail of the less-than-best-effort queue)
5 : 04 04 04 04 04 04 04 04 04 04
6 : 04 04 04 04 ! This section configures interface egress queuing parameters
cr36-3750s-SS100(config)#interface range GigabitEthernet1/0/1-48
cr35-4507-SS1#show qos interface Gig1/2 cr36-3750s-SS100(config-if-range)# queue-set 1
QoS is enabled globally ! The interface(s) is assigned to queue-set 1
Port QoS is enabled cr36-3750s-SS100(config-if-range)# srr-queue bandwidth share 1 30 35 5
Administrative Port Trust State: 'dscp' ! The SRR sharing weights are set to allocate 30% BW to Q2
Operational Port Trust State: 'dscp' ! 35% BW to Q3 and 5% BW to Q4
Trust device: none ! Q1 SRR sharing weight is ignored, as it will be configured as a PQ
Default DSCP: 0 Default CoS: 0 cr36-3750s-SS100(config-if-range)# priority-queue out
Appliance trust: none ! Q1 is enabled as a strict priority queue
Tx-Queue Bandwidth ShapeRate Priority QueueSize
(bps) (bps) (packets) cr36-3750s-SS100#show mls qos interface GigabitEthernet1/0/49 queueing
1 50000000 disabled N/A 2080 GigabitEthernet1/0/49
2 350000000 disabled N/A2080 Egress Priority Queue : enabled
3 300000000disabled high2080 Shaped queue weights (absolute) : 25 0 0 0
4 300000000disabledN/A2080 Shared queue weights : 1 30 35 5
The port bandwidth limit : 100 (Operational Bandwidth:100.0)
The port is mapped to qset : 1
Deploying Small School Site Egress QoS

Collapsed Core—Catalyst 3750-E StackWise Plus


The small school site is deployed with Cisco Catalyst 3750-E StackWise as the collapsed
core router.
The Catalyst 3750-E can have up to four egress queues. Before forwarding egress traffic,
each packet is placed in the appropriate egress-queue as shown in Figure 10. The
Catalyst 3750-E switch supports Shaped Round Robin (SRR) packet schedule service
which can be deployed in two different modes:
• Shaped—To provide guaranteed bandwidth, the shaped egress queue reserves
some of the bandwidth of the port for each queue. Traffic load exceeding the shape
parameter gets dropped. The queue cannot take advantage of excess bandwidth
capacity when other queues are not using their bandwidth allocations.
• Shared—Shared mode also provides guaranteed bandwidth for each queue;
however, it allows the flexibility of using excess bandwidth when there is any available.
The following sample configuration shows how to implement egress QoS on the Catalyst
3750-E:
Schools QoS Deployment Guide SBA

You might also like