13.1 Quality of Service (QoS) Classification and Marking
Key Takeaways
Quality of Service (QoS) allocates finite campus bandwidth, mitigating latency, jitter, and packet loss for delay-sensitive real-time applications such as Voice over IP (VoIP) and interactive video.
Layer 2 Class of Service (CoS) uses the 3-bit Priority Code Point (PCP) field in 802.1Q tags (values 0–7), but these markings are non-routable and discarded when crossing Layer 3 boundaries.
Layer 3 Differentiated Services Code Point (DSCP) provides 64 distinct priority markings (0–63) using 6 bits of the IP header, categorizing traffic into Default Forwarding (DF), Expedited Forwarding (EF / DSCP 46), and Assured Forwarding (AF) classes.
The QoS trust boundary dictates whether a switch preserves incoming packet markings or strips them to Best Effort (DSCP 0); access ports connecting to untrusted end-user PCs must reset markings, while ports connecting to IP phones or APs are trusted.
AOS-CX sets trust globally or per interface with
qos trust {none | cos | dscp}; the default is none, which ignores packet markings for queuing, and markings are rewritten only if a port remark such asqos dscp 0is configured.
Quality of Service (QoS) Classification and Marking
Quick Summary: Enterprise campus networks transport diverse traffic streams over shared switching infrastructure—from latency-intolerant Voice over IP (VoIP) and interactive video to bursty database transactions and non-critical web browsing. Without Quality of Service (QoS), all packets are treated with equal best-effort forwarding, resulting in audio clipping, video freezing, and application timeouts during transient uplink congestion. By implementing structured classification, marking, and trust boundaries, network administrators categorize campus traffic at the edge and apply standardized Layer 2 (802.1p CoS) and Layer 3 (DSCP) tags that guarantee predictable end-to-end performance.
Campus QoS Fundamentals and Performance Metrics
Quality of Service refers to the collection of networking technologies and techniques that manage network resources to provide differentiated forwarding treatments to specific traffic categories. When network demand exceeds available link capacity, switches experience buffer congestion. QoS does not generate additional physical bandwidth; instead, it intelligently allocates available bandwidth according to administrative policy.
Primary Network Performance Metrics
QoS mechanisms directly manage four fundamental network health metrics:
- Bandwidth (Throughput Capacity): The total volume of data bits that can be transmitted across a physical or logical channel per second (e.g., 1 Gbps, 10 Gbps). Video streaming and large file transfers require sustained throughput, whereas voice calls demand minimal bandwidth (~80–100 kbps per call using the G.711 codec) but require immediate transit.
- Delay / Latency (Transit Time): The total time required for a data packet to travel from its source endpoint to its destination. Latency consists of propagation delay, serialization delay, processing delay, and queuing delay. For interactive voice communication, industry standards require one-way end-to-end latency to remain below 150 milliseconds (ITU-T G.114).
- Jitter (Delay Variation): The statistical variance in packet arrival intervals. If voice packets leave a sender spaced exactly 20 ms apart but arrive in bursts spaced 5 ms and 40 ms apart due to queuing fluctuations, the receiving endpoint's jitter buffer can underflow or overflow, causing audio stutter or dropped speech. Voice traffic requires jitter to remain below 30 milliseconds.
- Packet Loss (Drop Rate): The percentage of transmitted packets discarded along the forwarding path due to full buffer queues or transmission errors. While TCP applications recover from packet loss via retransmissions, real-time UDP applications (voice/video) cannot retransmit late packets. Voice traffic tolerates less than 1% packet loss before intelligibility degrades sharply.
Campus Traffic Profiles
Enterprise campus environments divide traffic into distinct operational classes:
| Traffic Class | Examples | Sensitivity to Latency | Sensitivity to Jitter | Tolerance to Packet Loss | Bandwidth Demands |
|---|---|---|---|---|---|
| Voice | VoIP RTP audio, SIP calls | Extremely High (<150 ms) | Extremely High (<30 ms) | Extremely Low (<1%) | Very Low (64–100 kbps/call) |
| Interactive Video | Zoom, Microsoft Teams, Cisco Webex | High (<200 ms) | High (<30 ms) | Low (<1–2%) | Moderate to High (1–5 Mbps) |
| Streaming Video | Training webinars, IPTV | Moderate (can buffer) | Low (jitter buffer absorbed) | Low (<2%) | Moderate to High (2–10 Mbps) |
| Mission-Critical Data | ERP (SAP, Oracle), POS, Database SQL | Moderate to High | Low | Zero (TCP retransmits) | Bursty (variable) |
| Best Effort | General web browsing, email, DNS | Low (no guarantees) | Low | High | Variable |
| Scavenger | P2P file transfers, personal video | Lowest (deprioritized) | None | High (first to drop) | Managed / throttled |
Layer 2 Classification and Marking: IEEE 802.1p CoS
When Ethernet frames travel over tagged trunk links, Layer 2 Quality of Service is implemented using IEEE 802.1p Class of Service (CoS), which is embedded directly within the 4-byte IEEE 802.1Q VLAN header.
+-------------------------------------------------------------------------+
| IEEE 802.1Q TAG STRUCTURE |
| |
| TPID (16 bits) | TCI (16 bits) |
| 0x8100 | PCP (3 bits) | DEI (1 bit) | VID (12 bits) |
| | CoS 0 to 7 | Drop Eligible| VLAN Identifier |
+-------------------------------------------------------------------------+
The Priority Code Point (PCP) Field
The Tag Control Information (TCI) field contains the 3-bit Priority Code Point (PCP), which provides 8 distinct priority values numbered from 0 to 7 (2^3 = 8):
- CoS 0 (Best Effort): Default priority assigned to standard data traffic.
- CoS 1 (Background / Scavenger): Lowest priority data traffic.
- CoS 2 (Spare / Excellent Effort): Standard business applications.
- CoS 3 (Critical Applications): Mission-critical transactional client-server applications.
- CoS 4 (Video): Latency-sensitive streaming and interactive video conferencing.
- CoS 5 (Voice): Real-time interactive voice RTP streams.
- CoS 6 (Internetwork Control): Routing protocol traffic (e.g., OSPF, BGP) requiring priority delivery.
- CoS 7 (Network Control): Layer 2 link-level control frames (e.g., STP BPDUs, LACP, LLDP).
Architectural Limitation of Layer 2 CoS
Because CoS is contained strictly within the 802.1Q Ethernet header, it exists only on Layer 2 tagged frames. As soon as a frame enters an untagged access port or traverses a Layer 3 routing boundary (such as an Aruba CX switch routing between VLAN SVIs or routing upstream to a core firewall), the switch strips the Layer 2 Ethernet header and rewrites a new Layer 2 frame. Consequently, CoS markings are lost across Layer 3 boundaries unless the switch maps the incoming CoS value to a corresponding Layer 3 DSCP value before routing.
Layer 3 Classification and Marking: Type of Service (ToS) and DSCP
To ensure QoS markings persist end-to-end across routed enterprise networks and WANs, classification and marking are performed at the Network layer (Layer 3) inside the IP packet header.
Historical Context: IPv4 Type of Service (ToS) Byte
The original IPv4 header defined an 8-bit Type of Service (ToS) byte (RFC 791). The first 3 bits represented IP Precedence (IPP), providing 8 priority levels (0 to 7), identical in concept to Layer 2 CoS. The remaining bits represented Delay, Throughput, and Reliability flags. However, 8 priority levels proved too coarse for complex enterprise networks.
Modern Standard: Differentiated Services (DiffServ / RFC 2474)
The IETF Differentiated Services (DiffServ) architecture redefined the IPv4 ToS byte and the IPv6 Traffic Class byte into two distinct functional fields:
+-------------------------------------------------------------------------+
| DIFFERENTIATED SERVICES BYTE |
| |
| Bit 0 Bit 1 Bit 2 Bit 3 Bit 4 Bit 5 | Bit 6 Bit 7 |
| <------------------ DSCP (6 bits) -----------> | <-- ECN (2 bits) -> |
| 64 Codepoints (0 to 63) | Explicit Congestion |
+-------------------------------------------------------------------------+
- Differentiated Services Code Point (DSCP, 6 bits): Occupies bits 0 through 5, providing 64 unique priority values (2^6 = 64, decimal values 0 to 63).
- Explicit Congestion Notification (ECN, 2 bits): Occupies bits 6 and 7 (RFC 3168), allowing routers and switches to signal congestion to endpoints without dropping packets.
Standard Differentiated Services Per-Hop Behaviors (PHB)
A Per-Hop Behavior (PHB) describes the forwarding treatment (scheduling, queuing, and drop precedence) that a DiffServ-compliant switch or router applies to a packet carrying a specific DSCP value.
1. Default Forwarding (DF)
- DSCP Value:
0(Binary:000000/ CS0) - Description: Standard best-effort forwarding. Provides no bandwidth guarantees and receives standard tail-drop treatment during congestion.
2. Expedited Forwarding (EF - RFC 3246)
- DSCP Value:
46(Binary:101110) - Description: Designed for delay-sensitive, jitter-intolerant, real-time services. Guarantees strict priority queuing and low latency. EF is the universal standard marking for Voice over IP RTP audio streams.
3. Assured Forwarding (AF - RFC 2597)
The Assured Forwarding model defines four distinct traffic classes (Class 1 to Class 4). Within each class, packets are assigned one of three drop precedence levels (Low, Medium, or High):
- The notation is written as AFxy, where x is the Class (1 to 4) and y is the Drop Precedence (1 to 3).
- Class Selection (x): Class 4 represents the highest priority data queue; Class 1 represents the lowest.
- Drop Precedence (y): Level 1 has the lowest probability of being dropped during congestion; Level 3 has the highest probability of being dropped.
DSCP Decimal Calculation: DSCP = 8x + 2y
Example for AF41: (8 * 4) + (2 * 1) = 32 + 2 = 34
Example for AF42: (8 * 4) + (2 * 2) = 32 + 4 = 36
Example for AF43: (8 * 4) + (2 * 3) = 32 + 6 = 38
| AF Class | Low Drop (y=1) | Medium Drop (y=2) | High Drop (y=3) | Target Traffic Profile |
|---|---|---|---|---|
| Class 4 (AF4y) | AF41 (DSCP 34) | AF42 (DSCP 36) | AF43 (DSCP 38) | Interactive Video Conferencing |
| Class 3 (AF3y) | AF31 (DSCP 26) | AF32 (DSCP 28) | AF33 (DSCP 30) | Streaming Video / Critical Apps |
| Class 2 (AF2y) | AF21 (DSCP 18) | AF22 (DSCP 20) | AF23 (DSCP 22) | High-Priority Business Data |
| Class 1 (AF1y) | AF11 (DSCP 10) | AF12 (DSCP 12) | AF13 (DSCP 14) | Bulk Data / Low-Priority Apps |
4. Class Selector (CS)
Class Selector codepoints (CS0 to CS7) maintain backward compatibility with legacy 3-bit IP Precedence. The 3 most significant bits of the DSCP field mirror the IP Precedence value, while the last 3 bits are set to 000 (e.g., CS5 = binary 101000 = decimal 40, used for voice signaling/SIP; CS6 = binary 110000 = decimal 48, used for network control).
QoS Trust Boundaries and Enforcement
A QoS Trust Boundary is the demarcation line in a network where incoming QoS markings are either accepted as genuine ("trusted") or disregarded and overwritten ("untrusted"). Establishing proper trust boundaries is critical for campus stability:
[ Untrusted PC ] ------ (Untrusted Port: Strip to DSCP 0) -----> [ Access Switch ]
|
[ Trusted IP Phone ] --- (Trusted Port: Trust CoS / DSCP) -------> [ Access Switch ]
| (PC Port on Phone)
+--- [ End-User PC ] (Untrusted: Phone remarks PC to CoS 0)
The Risk of Untrusted Markings
If all switch access ports trust incoming client markings by default, any end-user or rogue software can maliciously mark bulk downloads or BitTorrent streams with DSCP 46 (EF). The switch would place those bulk streams into the voice priority queue, starving legitimate corporate voice calls.
Trust Boundary Rules
- Untrusted Access Ports: Standard client access ports connected to desktop PCs, laptops, network printers, and guest devices must be treated as untrusted, so their markings do not affect queuing. Add a remark (for example
qos dscp 0) if the marking must also be rewritten before the packet travels further. - Trusted Edge Endpoints: Ports connected to verified infrastructure devices—such as VoIP phones, enterprise wireless Access Points (APs), and video conferencing codecs—are designated as trusted.
- The IP Phone Daisy-Chain Architecture: In enterprise offices, a desktop PC is frequently connected to the secondary PC data port of an IP phone, which connects to the access switch over a single cable. The switch uses LLDP-MED Network Policy to advertise the voice VLAN and the priority values the phone should use for its own voice traffic (for example CoS 5 / DSCP 46). Re-marking the PC's traffic is a feature of the phone's own configuration (many enterprise phones reset PC-port markings to 0); LLDP-MED does not control it. Because AOS-CX trust is set per port, a port that trusts DSCP also trusts the PC's markings unless the phone re-marks them or a classifier policy on the port overrides them.
AOS-CX QoS Trust Configuration and Verification
Aruba AOS-CX switches provide granular control over QoS trust states at the global and per-interface levels.
Trust States in AOS-CX
qos trust none(the default): The interface is untrusted. The switch ignores packet headers and assigns every packet the local priority and color configured for CoS-map entry 0. The packet's DSCP is not changed unless you also configure a port remark such asqos dscp 0, which works only while trust is none.qos trust cos: The interface trusts Layer 2 802.1p CoS markings. The switch inspects the 802.1Q PCP bits and maps them to an internal Local Priority (0–7) using the activecos-maptable. If the packet is untagged, it receives the port's default CoS.qos trust dscp: The interface trusts Layer 3 DSCP markings. The switch inspects the 6-bit DSCP field in the IP header and maps it to an internal Local Priority (0–7) using the activedscp-maptable.
Interface Configuration Workflow
switch# configure
switch(config)# interface 1/1/10
switch(config-if)# description Untrusted-Workstation-Port
switch(config-if)# qos trust none
switch(config-if)# qos dscp 0
switch(config-if)# exit
switch(config)# interface 1/1/11
switch(config-if)# description Trusted-VoIP-Phone-Port
switch(config-if)# qos trust dscp
switch(config-if)# exit
switch(config)# interface 1/1/48
switch(config-if)# description Uplink-to-Aggregation
switch(config-if)# qos trust dscp
switch(config-if)# exit
Verifying Trust Configuration
To inspect interface trust states and active mapping tables on AOS-CX (abbreviated, simplified output):
switch# show interface 1/1/10 qos
QoS Trust Settings (simplified):
Interface Trust State Default CoS Default DSCP
--------- ----------- ----------- ------------
1/1/10 none 0 0
1/1/11 dscp 0 0
1/1/48 dscp 0 0
switch# show qos dscp-map
DSCP Local-Priority Color
---- -------------- -----
0 1 green
10 1 green
26 3 green
34 4 green
46 5 green
48 6 green
A network administrator is designing a QoS marking policy for video conferencing and interactive media streams using the Differentiated Services Assured Forwarding (AF) model. The design requires video streams to be assigned to Class 4 with a Medium drop precedence. What is the standard IETF name and corresponding decimal DSCP value for this traffic class?
AF43 with a decimal DSCP value of 38
AF23 with a decimal DSCP value of 22
AF41 with a decimal DSCP value of 34
AF42 with a decimal DSCP value of 36
In an office deployment, an employee connects a personal desktop computer to the secondary PC data port of an enterprise IP phone, which connects directly to port 1/1/10 on an Aruba CX 6200 switch. The administrator observes that when the PC runs high-bandwidth file transfers, office VoIP calls experience severe audio degradation. Investigation reveals that the PC operating system has been manually configured to transmit all TCP packets with DSCP 46. What QoS configuration on the switch resolves this issue?
Configure 'qos trust none' globally so that no packet on any port receives queuing priority
Trust DSCP on port 1/1/10 and apply a classifier policy that re-marks the PC's data-VLAN traffic to DSCP 0
Configure 'qos trust cos' on port 1/1/10 and remove the voice VLAN so all traffic uses native VLAN 1
Configure 'rate-limit broadcast 100 kbps' on port 1/1/10 to throttle both the phone and the PC
An enterprise network carries video surveillance traffic from access switches to a central recording server located across a routed campus distribution core. The access switch ports are configured to mark surveillance video with Layer 2 802.1p Class of Service (CoS) value 4. However, after packets cross the default gateway SVI on the distribution switch, the core switches forward the surveillance packets with default best-effort priority. What is the fundamental cause of this behavior?
The access switches must run in half-duplex mode to preserve the 802.1Q priority code point value
CoS lives in the 802.1Q tag, which is removed when the packet is routed across a Layer 3 boundary
CoS 4 is reserved for spanning-tree BPDUs and cannot be forwarded by Layer 3 SVIs on the core switch
AOS-CX core switches disable all egress hardware queues when routing traffic between OSPF areas
Sections you finish are checked off in the contents.