13.1 Quality of Service (QoS) Classification and Marking

Key Takeaways

  • Quality of Service (QoS) allocates finite campus bandwidth, mitigating latency, jitter, and packet loss for delay-sensitive real-time applications such as Voice over IP (VoIP) and interactive video.

  • Layer 2 Class of Service (CoS) uses the 3-bit Priority Code Point (PCP) field in 802.1Q tags (values 0–7), but these markings are non-routable and discarded when crossing Layer 3 boundaries.

  • Layer 3 Differentiated Services Code Point (DSCP) provides 64 distinct priority markings (0–63) using 6 bits of the IP header, categorizing traffic into Default Forwarding (DF), Expedited Forwarding (EF / DSCP 46), and Assured Forwarding (AF) classes.

  • The QoS trust boundary dictates whether a switch preserves incoming packet markings or strips them to Best Effort (DSCP 0); access ports connecting to untrusted end-user PCs must reset markings, while ports connecting to IP phones or APs are trusted.

  • AOS-CX sets trust globally or per interface with qos trust {none | cos | dscp}; the default is none, which ignores packet markings for queuing, and markings are rewritten only if a port remark such as qos dscp 0 is configured.

Last updated: October 2026

Quality of Service (QoS) Classification and Marking

Quick Summary: Enterprise campus networks transport diverse traffic streams over shared switching infrastructure—from latency-intolerant Voice over IP (VoIP) and interactive video to bursty database transactions and non-critical web browsing. Without Quality of Service (QoS), all packets are treated with equal best-effort forwarding, resulting in audio clipping, video freezing, and application timeouts during transient uplink congestion. By implementing structured classification, marking, and trust boundaries, network administrators categorize campus traffic at the edge and apply standardized Layer 2 (802.1p CoS) and Layer 3 (DSCP) tags that guarantee predictable end-to-end performance.


Campus QoS Fundamentals and Performance Metrics

Quality of Service refers to the collection of networking technologies and techniques that manage network resources to provide differentiated forwarding treatments to specific traffic categories. When network demand exceeds available link capacity, switches experience buffer congestion. QoS does not generate additional physical bandwidth; instead, it intelligently allocates available bandwidth according to administrative policy.

Primary Network Performance Metrics

QoS mechanisms directly manage four fundamental network health metrics:

  1. Bandwidth (Throughput Capacity): The total volume of data bits that can be transmitted across a physical or logical channel per second (e.g., 1 Gbps, 10 Gbps). Video streaming and large file transfers require sustained throughput, whereas voice calls demand minimal bandwidth (~80–100 kbps per call using the G.711 codec) but require immediate transit.
  2. Delay / Latency (Transit Time): The total time required for a data packet to travel from its source endpoint to its destination. Latency consists of propagation delay, serialization delay, processing delay, and queuing delay. For interactive voice communication, industry standards require one-way end-to-end latency to remain below 150 milliseconds (ITU-T G.114).
  3. Jitter (Delay Variation): The statistical variance in packet arrival intervals. If voice packets leave a sender spaced exactly 20 ms apart but arrive in bursts spaced 5 ms and 40 ms apart due to queuing fluctuations, the receiving endpoint's jitter buffer can underflow or overflow, causing audio stutter or dropped speech. Voice traffic requires jitter to remain below 30 milliseconds.
  4. Packet Loss (Drop Rate): The percentage of transmitted packets discarded along the forwarding path due to full buffer queues or transmission errors. While TCP applications recover from packet loss via retransmissions, real-time UDP applications (voice/video) cannot retransmit late packets. Voice traffic tolerates less than 1% packet loss before intelligibility degrades sharply.

Campus Traffic Profiles

Enterprise campus environments divide traffic into distinct operational classes:

Traffic ClassExamplesSensitivity to LatencySensitivity to JitterTolerance to Packet LossBandwidth Demands
VoiceVoIP RTP audio, SIP callsExtremely High (<150 ms)Extremely High (<30 ms)Extremely Low (<1%)Very Low (64–100 kbps/call)
Interactive VideoZoom, Microsoft Teams, Cisco WebexHigh (<200 ms)High (<30 ms)Low (<1–2%)Moderate to High (1–5 Mbps)
Streaming VideoTraining webinars, IPTVModerate (can buffer)Low (jitter buffer absorbed)Low (<2%)Moderate to High (2–10 Mbps)
Mission-Critical DataERP (SAP, Oracle), POS, Database SQLModerate to HighLowZero (TCP retransmits)Bursty (variable)
Best EffortGeneral web browsing, email, DNSLow (no guarantees)LowHighVariable
ScavengerP2P file transfers, personal videoLowest (deprioritized)NoneHigh (first to drop)Managed / throttled

Layer 2 Classification and Marking: IEEE 802.1p CoS

When Ethernet frames travel over tagged trunk links, Layer 2 Quality of Service is implemented using IEEE 802.1p Class of Service (CoS), which is embedded directly within the 4-byte IEEE 802.1Q VLAN header.

+-------------------------------------------------------------------------+
|                       IEEE 802.1Q TAG STRUCTURE                         |
|                                                                         |
|   TPID (16 bits)   |                 TCI (16 bits)                      |
|   0x8100           |  PCP (3 bits)  |  DEI (1 bit)  |  VID (12 bits)    |
|                    |  CoS 0 to 7    |  Drop Eligible|  VLAN Identifier  |
+-------------------------------------------------------------------------+

The Priority Code Point (PCP) Field

The Tag Control Information (TCI) field contains the 3-bit Priority Code Point (PCP), which provides 8 distinct priority values numbered from 0 to 7 (2^3 = 8):

  • CoS 0 (Best Effort): Default priority assigned to standard data traffic.
  • CoS 1 (Background / Scavenger): Lowest priority data traffic.
  • CoS 2 (Spare / Excellent Effort): Standard business applications.
  • CoS 3 (Critical Applications): Mission-critical transactional client-server applications.
  • CoS 4 (Video): Latency-sensitive streaming and interactive video conferencing.
  • CoS 5 (Voice): Real-time interactive voice RTP streams.
  • CoS 6 (Internetwork Control): Routing protocol traffic (e.g., OSPF, BGP) requiring priority delivery.
  • CoS 7 (Network Control): Layer 2 link-level control frames (e.g., STP BPDUs, LACP, LLDP).

Architectural Limitation of Layer 2 CoS

Because CoS is contained strictly within the 802.1Q Ethernet header, it exists only on Layer 2 tagged frames. As soon as a frame enters an untagged access port or traverses a Layer 3 routing boundary (such as an Aruba CX switch routing between VLAN SVIs or routing upstream to a core firewall), the switch strips the Layer 2 Ethernet header and rewrites a new Layer 2 frame. Consequently, CoS markings are lost across Layer 3 boundaries unless the switch maps the incoming CoS value to a corresponding Layer 3 DSCP value before routing.


Layer 3 Classification and Marking: Type of Service (ToS) and DSCP

To ensure QoS markings persist end-to-end across routed enterprise networks and WANs, classification and marking are performed at the Network layer (Layer 3) inside the IP packet header.

Historical Context: IPv4 Type of Service (ToS) Byte

The original IPv4 header defined an 8-bit Type of Service (ToS) byte (RFC 791). The first 3 bits represented IP Precedence (IPP), providing 8 priority levels (0 to 7), identical in concept to Layer 2 CoS. The remaining bits represented Delay, Throughput, and Reliability flags. However, 8 priority levels proved too coarse for complex enterprise networks.

Modern Standard: Differentiated Services (DiffServ / RFC 2474)

The IETF Differentiated Services (DiffServ) architecture redefined the IPv4 ToS byte and the IPv6 Traffic Class byte into two distinct functional fields:

+-------------------------------------------------------------------------+
|                    DIFFERENTIATED SERVICES BYTE                         |
|                                                                         |
|   Bit 0   Bit 1   Bit 2   Bit 3   Bit 4   Bit 5  |   Bit 6     Bit 7    |
|   <------------------ DSCP (6 bits) -----------> |  <-- ECN (2 bits) -> |
|             64 Codepoints (0 to 63)              |  Explicit Congestion |
+-------------------------------------------------------------------------+
  1. Differentiated Services Code Point (DSCP, 6 bits): Occupies bits 0 through 5, providing 64 unique priority values (2^6 = 64, decimal values 0 to 63).
  2. Explicit Congestion Notification (ECN, 2 bits): Occupies bits 6 and 7 (RFC 3168), allowing routers and switches to signal congestion to endpoints without dropping packets.

Standard Differentiated Services Per-Hop Behaviors (PHB)

A Per-Hop Behavior (PHB) describes the forwarding treatment (scheduling, queuing, and drop precedence) that a DiffServ-compliant switch or router applies to a packet carrying a specific DSCP value.

1. Default Forwarding (DF)

  • DSCP Value: 0 (Binary: 000000 / CS0)
  • Description: Standard best-effort forwarding. Provides no bandwidth guarantees and receives standard tail-drop treatment during congestion.

2. Expedited Forwarding (EF - RFC 3246)

  • DSCP Value: 46 (Binary: 101110)
  • Description: Designed for delay-sensitive, jitter-intolerant, real-time services. Guarantees strict priority queuing and low latency. EF is the universal standard marking for Voice over IP RTP audio streams.

3. Assured Forwarding (AF - RFC 2597)

The Assured Forwarding model defines four distinct traffic classes (Class 1 to Class 4). Within each class, packets are assigned one of three drop precedence levels (Low, Medium, or High):

  • The notation is written as AFxy, where x is the Class (1 to 4) and y is the Drop Precedence (1 to 3).
  • Class Selection (x): Class 4 represents the highest priority data queue; Class 1 represents the lowest.
  • Drop Precedence (y): Level 1 has the lowest probability of being dropped during congestion; Level 3 has the highest probability of being dropped.
DSCP Decimal Calculation: DSCP = 8x + 2y
Example for AF41: (8 * 4) + (2 * 1) = 32 + 2 = 34
Example for AF42: (8 * 4) + (2 * 2) = 32 + 4 = 36
Example for AF43: (8 * 4) + (2 * 3) = 32 + 6 = 38
AF ClassLow Drop (y=1)Medium Drop (y=2)High Drop (y=3)Target Traffic Profile
Class 4 (AF4y)AF41 (DSCP 34)AF42 (DSCP 36)AF43 (DSCP 38)Interactive Video Conferencing
Class 3 (AF3y)AF31 (DSCP 26)AF32 (DSCP 28)AF33 (DSCP 30)Streaming Video / Critical Apps
Class 2 (AF2y)AF21 (DSCP 18)AF22 (DSCP 20)AF23 (DSCP 22)High-Priority Business Data
Class 1 (AF1y)AF11 (DSCP 10)AF12 (DSCP 12)AF13 (DSCP 14)Bulk Data / Low-Priority Apps

4. Class Selector (CS)

Class Selector codepoints (CS0 to CS7) maintain backward compatibility with legacy 3-bit IP Precedence. The 3 most significant bits of the DSCP field mirror the IP Precedence value, while the last 3 bits are set to 000 (e.g., CS5 = binary 101000 = decimal 40, used for voice signaling/SIP; CS6 = binary 110000 = decimal 48, used for network control).


QoS Trust Boundaries and Enforcement

A QoS Trust Boundary is the demarcation line in a network where incoming QoS markings are either accepted as genuine ("trusted") or disregarded and overwritten ("untrusted"). Establishing proper trust boundaries is critical for campus stability:

[ Untrusted PC ] ------ (Untrusted Port: Strip to DSCP 0) -----> [ Access Switch ]
                                                                         |
[ Trusted IP Phone ] --- (Trusted Port: Trust CoS / DSCP) -------> [ Access Switch ]
      | (PC Port on Phone)
      +--- [ End-User PC ] (Untrusted: Phone remarks PC to CoS 0)

The Risk of Untrusted Markings

If all switch access ports trust incoming client markings by default, any end-user or rogue software can maliciously mark bulk downloads or BitTorrent streams with DSCP 46 (EF). The switch would place those bulk streams into the voice priority queue, starving legitimate corporate voice calls.

Trust Boundary Rules

  1. Untrusted Access Ports: Standard client access ports connected to desktop PCs, laptops, network printers, and guest devices must be treated as untrusted, so their markings do not affect queuing. Add a remark (for example qos dscp 0) if the marking must also be rewritten before the packet travels further.
  2. Trusted Edge Endpoints: Ports connected to verified infrastructure devices—such as VoIP phones, enterprise wireless Access Points (APs), and video conferencing codecs—are designated as trusted.
  3. The IP Phone Daisy-Chain Architecture: In enterprise offices, a desktop PC is frequently connected to the secondary PC data port of an IP phone, which connects to the access switch over a single cable. The switch uses LLDP-MED Network Policy to advertise the voice VLAN and the priority values the phone should use for its own voice traffic (for example CoS 5 / DSCP 46). Re-marking the PC's traffic is a feature of the phone's own configuration (many enterprise phones reset PC-port markings to 0); LLDP-MED does not control it. Because AOS-CX trust is set per port, a port that trusts DSCP also trusts the PC's markings unless the phone re-marks them or a classifier policy on the port overrides them.

AOS-CX QoS Trust Configuration and Verification

Aruba AOS-CX switches provide granular control over QoS trust states at the global and per-interface levels.

Trust States in AOS-CX

  • qos trust none (the default): The interface is untrusted. The switch ignores packet headers and assigns every packet the local priority and color configured for CoS-map entry 0. The packet's DSCP is not changed unless you also configure a port remark such as qos dscp 0, which works only while trust is none.
  • qos trust cos: The interface trusts Layer 2 802.1p CoS markings. The switch inspects the 802.1Q PCP bits and maps them to an internal Local Priority (0–7) using the active cos-map table. If the packet is untagged, it receives the port's default CoS.
  • qos trust dscp: The interface trusts Layer 3 DSCP markings. The switch inspects the 6-bit DSCP field in the IP header and maps it to an internal Local Priority (0–7) using the active dscp-map table.

Interface Configuration Workflow

switch# configure
switch(config)# interface 1/1/10
switch(config-if)# description Untrusted-Workstation-Port
switch(config-if)# qos trust none
switch(config-if)# qos dscp 0
switch(config-if)# exit

switch(config)# interface 1/1/11
switch(config-if)# description Trusted-VoIP-Phone-Port
switch(config-if)# qos trust dscp
switch(config-if)# exit

switch(config)# interface 1/1/48
switch(config-if)# description Uplink-to-Aggregation
switch(config-if)# qos trust dscp
switch(config-if)# exit

Verifying Trust Configuration

To inspect interface trust states and active mapping tables on AOS-CX (abbreviated, simplified output):

switch# show interface 1/1/10 qos
 QoS Trust Settings (simplified):

Interface   Trust State   Default CoS   Default DSCP
---------   -----------   -----------   ------------
1/1/10      none          0             0
1/1/11      dscp          0             0
1/1/48      dscp          0             0

switch# show qos dscp-map
DSCP   Local-Priority   Color
----   --------------   -----
0      1                green
10     1                green
26     3                green
34     4                green
46     5                green
48     6                green
Loading diagram...
Campus QoS Trust Boundary and Traffic Classification Model
Test Your Knowledge

A network administrator is designing a QoS marking policy for video conferencing and interactive media streams using the Differentiated Services Assured Forwarding (AF) model. The design requires video streams to be assigned to Class 4 with a Medium drop precedence. What is the standard IETF name and corresponding decimal DSCP value for this traffic class?

A

AF43 with a decimal DSCP value of 38

B

AF23 with a decimal DSCP value of 22

C

AF41 with a decimal DSCP value of 34

D

AF42 with a decimal DSCP value of 36

Test Your Knowledge

In an office deployment, an employee connects a personal desktop computer to the secondary PC data port of an enterprise IP phone, which connects directly to port 1/1/10 on an Aruba CX 6200 switch. The administrator observes that when the PC runs high-bandwidth file transfers, office VoIP calls experience severe audio degradation. Investigation reveals that the PC operating system has been manually configured to transmit all TCP packets with DSCP 46. What QoS configuration on the switch resolves this issue?

A

Configure 'qos trust none' globally so that no packet on any port receives queuing priority

B

Trust DSCP on port 1/1/10 and apply a classifier policy that re-marks the PC's data-VLAN traffic to DSCP 0

C

Configure 'qos trust cos' on port 1/1/10 and remove the voice VLAN so all traffic uses native VLAN 1

D

Configure 'rate-limit broadcast 100 kbps' on port 1/1/10 to throttle both the phone and the PC

Test Your Knowledge

An enterprise network carries video surveillance traffic from access switches to a central recording server located across a routed campus distribution core. The access switch ports are configured to mark surveillance video with Layer 2 802.1p Class of Service (CoS) value 4. However, after packets cross the default gateway SVI on the distribution switch, the core switches forward the surveillance packets with default best-effort priority. What is the fundamental cause of this behavior?

A

The access switches must run in half-duplex mode to preserve the 802.1Q priority code point value

B

CoS lives in the 802.1Q tag, which is removed when the packet is routed across a Layer 3 boundary

C

CoS 4 is reserved for spanning-tree BPDUs and cannot be forwarded by Layer 3 SVIs on the core switch

D

AOS-CX core switches disable all egress hardware queues when routing traffic between OSPF areas

Sections you finish are checked off in the contents.