400
C
HAPTER
19: C
ONFIGURING
AND
M
ANAGING
S
ECURITY
ACL
S
Table 34 lists the CoS values to use when reassigning traffic to a different
priority. The CoS determines the MAP forwarding queue to use for the
traffic when sending it to a wireless client.
Using the dscp Option
The easiest way to filter based on DSCP is to use the
dscp
codepoint
option. The following commands remap IP packets from IP address
10.10.50.2 that have DSCP value 46 to have CoS value 7 when they are
forwarded to any 10.10.90.x address on Distributed MAP 4:
WX1200#
set security acl ip acl2 permit cos 7 ip 10.10.50.2
0.0.0.0 10.10.90.0 0.0.0.255 dscp 46
success: change accepted.
WX1200#
set security acl ip acl2 permit any
success: change accepted.
WX1200#
commit security acl acl2
success: change accepted.
WX1200#
set security acl map acl2 ap 4 out
success: change accepted.
Using the precedence and tos Options
You also can indirectly filter on DSCP by filtering on both the IP
precedence and IP ToS values of a packet. However, this method requires
two ACEs. To use this method, specify the combination of precedence
and ToS values that is equivalent to the DSCP value. For example, to filter
based on DSCP value 46, configure an ACL that filters based on
precedence 5 and ToS 12. (To display a table of the precedence and ToS
combinations for each DSCP value, use the
display qos dscp-table
command.)
Table 34
Class-of-Service (CoS) Packet Handling
WMM Priority
Desired
CLI CoS Value to
Enter
Background
1
or
2
Best effort
0
or
3
Video
4
or
5
Voice
6
or
7
Summary of Contents for 3CRWX120695A
Page 138: ...138 CHAPTER 6 CONFIGURING AND MANAGING IP INTERFACES AND SERVICES ...
Page 272: ...272 CHAPTER 11 CONFIGURING RF LOAD BALANCING FOR MAPS ...
Page 310: ...310 CHAPTER 13 CONFIGURING USER ENCRYPTION ...
Page 322: ...322 CHAPTER 14 CONFIGURING RF AUTO TUNING ...
Page 350: ...350 CHAPTER 16 CONFIGURING QUALITY OF SERVICE ...
Page 368: ...368 CHAPTER 17 CONFIGURING AND MANAGING SPANNING TREE PROTOCOL ...
Page 412: ...412 CHAPTER 19 CONFIGURING AND MANAGING SECURITY ACLS ...
Page 518: ...518 CHAPTER 21 CONFIGURING AAA FOR NETWORK USERS ...
Page 530: ...530 CHAPTER 22 CONFIGURING COMMUNICATION WITH RADIUS ...
Page 542: ...542 CHAPTER 23 MANAGING 802 1X ON THE WX SWITCH ...
Page 598: ...598 CHAPTER 26 ROGUE DETECTION AND COUNTERMEASURES ...
Page 706: ...706 GLOSSARY ...