11.2 QoS Classification, Marking & Trust Boundaries
Key Takeaways
Layer 2 QoS operates within the IEEE 802.1Q tag using the 3-bit Priority Code Point (PCP) / Class of Service (CoS, values 0-7), where CoS 5 is designated for voice media, CoS 4 for video, and CoS 3 for call signaling.
Layer 3 QoS utilizes the 6-bit Differentiated Services Code Point (DSCP, values 0-63) inside the IPv4 ToS or IPv6 Traffic Class byte, providing 64 granular Per-Hop Behaviors (PHBs) compared to legacy 3-bit IP Precedence.
Assured Forwarding (AF) defines 4 classes and 3 drop precedences using the formula DSCP = 8 * Class + 2 * Drop Precedence; within any class, packets with higher drop precedence (e.g., AF43 vs AF41) are discarded first during queue congestion.
Cisco collaboration baseline markings mandate DSCP EF (46 / binary 101110) for voice media, AF41 (34) for interactive video, and CS3 (24) or AF31 (26) for collaboration call signaling.
The QoS trust boundary should be extended to the Cisco IP Phone using conditional trust (
switchport voice vlanandtrust device cisco-phone), allowing the phone to mark its own media as CoS 5 / DSCP EF while re-marking untrusted PC traffic to CoS 0 / DSCP 0.
11.2 QoS Classification, Marking & Trust Boundaries
Quality of Service (QoS) provides the foundational network mechanics required to protect real-time voice and video from being compromised by bursty data applications. Because network switches and routers cannot inherently distinguish between a critical VoIP media packet and a background file transfer, traffic must be classified (identified) and marked (tagged with priority metadata) as close to the ingress source as technically feasible. This section explores Layer 2 and Layer 3 marking standards, the Differentiated Services architecture, and the deployment of network trust boundaries.
1. Layer 2 QoS: IEEE 802.1Q & Class of Service (CoS)
At the data link layer (Layer 2), QoS markings reside within the IEEE 802.1Q frame header. When an Ethernet frame traverses an 802.1Q trunk or auxiliary voice VLAN, a 4-byte VLAN tag is inserted between the Source MAC Address and EtherType fields:
+-------------------------------------------------------------------------+
| IEEE 802.1Q ETHERNET HEADER |
| |
| +--------------------+-------------------+--------------------------+ |
| | Destination / Src | 802.1Q Tag Type | Tag Control Information | |
| | MAC (12 Bytes) | (TPID: 0x8100) | (TCI: 16 Bits / 2 Bytes) | |
| +--------------------+-------------------+--------------------------+ |
| | PCP/CoS | DEI | VLAN ID | |
| | (3 Bits)| (1) | (12 Bits)| |
| +---------+-----+----------+ |
+-------------------------------------------------------------------------+
The 3-Bit Priority Code Point (PCP)
The first 3 bits of the Tag Control Information (TCI) field represent the Priority Code Point (PCP), universally referred to in networking as Class of Service (CoS). Spanning 3 bits, CoS provides discrete priority levels (0 through 7):
| CoS Value | Binary | Standard Application | Cisco Collaboration Mapping |
|---|---|---|---|
| CoS 7 | 111 | Network Control / Reserved | Internal Switch / Spanning Tree Control |
| CoS 6 | 110 | Internetwork Control | Layer 3 Routing Protocol Keepalives |
| CoS 5 | 101 | Voice Media | Real-time Voice Payloads (RTP G.711 / G.729) |
| CoS 4 | 100 | Video Media | Interactive Real-Time Video (Webex / TelePresence) |
| CoS 3 | 011 | Call Control / Signaling | SIP, H.323, SCCP, MGCP, ICCS Signaling |
| CoS 2 | 010 | High-Priority Data | Business-Critical Transactional Data |
| CoS 1 | 001 | Medium-Priority Data | Scavenger / Background Traffic |
| CoS 0 | 000 | Best Effort | Standard Untagged Workstation Data |
Limitations of Layer 2 CoS
While CoS is vital for prioritizing traffic across local switch fabrics and Layer 2 trunk links, it possesses a severe architectural limitation: CoS is non-routable. The moment an Ethernet frame reaches a Layer 3 router hop, the router strips the Layer 2 header and 802.1Q tag to inspect the IP packet. If the priority marking is not mirrored into the Layer 3 IP header, the QoS classification is permanently lost across the routed network.
2. Layer 3 QoS: IP Precedence vs. DSCP
To preserve QoS markings across end-to-end multi-hop routed networks, priority metadata is encoded inside the Layer 3 IP header:
- In IPv4, QoS uses the 8-bit Type of Service (ToS) byte.
- In IPv6, QoS uses the 8-bit Traffic Class byte.
+-------------------------------------------------------------------------+
| LAYER 3 IP QUALITY OF SERVICE FIELD COMPARISON |
| |
| LEGACY IP PRECEDENCE (RFC 791): |
| +-------------------------------+---+---+---+-----------------------+ |
| | IP Precedence (Bits 0 - 2) | D | T | R | Unused (Bits 6 - 7) | |
| +-------------------------------+---+---+---+-----------------------+ |
| |
| DIFFERENTIATED SERVICES (DIFFSERV, RFC 2474 / 2475): |
| +-----------------------------------------------+-------------------+ |
| | DSCP: Differentiated Services Code Point | ECN: Explicit | |
| | (Bits 0 - 5, Values 0 - 63) | Congestion (6 - 7)| |
| +-----------------------------------------------+-------------------+ |
+-------------------------------------------------------------------------+
Legacy IP Precedence
Defined in RFC 791, IP Precedence (IPP) utilizes only the most significant 3 bits (bits 0 to 2) of the ToS byte, yielding 8 priority levels (0 to 7) that directly mirror Layer 2 CoS values. The subsequent three bits designated Delay (D), Throughput (T), and Reliability (R), though they were rarely implemented by networking hardware.
Differentiated Services (DiffServ)
Because 8 priority levels were insufficient for granular enterprise traffic policies, the IETF developed Differentiated Services (DiffServ, RFC 2474/2475). DiffServ redefines the ToS byte into two segments:
- Differentiated Services Code Point (DSCP): The upper 6 bits (bits 0 through 5), providing unique priority values (0 through 63).
- Explicit Congestion Notification (ECN, RFC 3168): The lowest 2 bits (bits 6 and 7), used by routers to signal impending queue congestion to endpoints without dropping packets.
3. DiffServ Per-Hop Behaviors (PHB)
DiffServ defines specific packet forwarding treatments called Per-Hop Behaviors (PHBs). A PHB instructs an intermediate router or switch on how to schedule, queue, and drop packets associated with a particular DSCP marking.
1. Default Forwarding (DF)
- Marking: DSCP 0 (
000000binary). - Behavior: Standard "Best Effort" forwarding. No bandwidth guarantees or latency bounds are provided.
2. Expedited Forwarding (EF - RFC 3246)
- Marking: DSCP 46 (
101110binary). - Behavior: Strict priority, low latency, low jitter, and guaranteed bandwidth service. Packets marked EF must be serviced by the router faster than the incoming line arrival rate to prevent queue buildup. EF is universally reserved for real-time voice media.
- Backward Compatibility: The first 3 bits of DSCP 46 (
101) equal decimal 5, ensuring full backward compatibility with IP Precedence 5 and CoS 5.
3. Assured Forwarding (AF - RFC 2597)
Assured Forwarding provides guaranteed bandwidth alongside selective drop precedence under congestion. AF defines 4 distinct Classes (Classes 1 through 4) and 3 Drop Precedences (Low, Medium, High):
- Drop Precedence 1 (Low Drop): The most protected packets in the class; dropped last during congestion.
- Drop Precedence 2 (Medium Drop): Moderate protection; dropped before drop precedence 1.
- Drop Precedence 3 (High Drop): The least protected packets in the class; dropped first during congestion.
The AF DSCP Mathematical Formula
Any AF code point can be calculated using the universal formula:
In binary notation, an AF packet takes the form cccdd0, where ccc represents the 3-bit class, dd represents the 2-bit drop precedence, and the 6th bit is always 0.
+-------------------------------------------------------------------------+
| ASSURED FORWARDING (AF) CODE POINT MATRIX |
| |
| DROP PRECEDENCE CLASS 1 CLASS 2 CLASS 3 CLASS 4 |
| =================== ========= ========= ========= ========= |
| Low Drop (Drop 1) AF11 (10) AF21 (18) AF31 (26) AF41 (34) |
| Medium Drop (Drop 2) AF12 (12) AF22 (20) AF32 (28) AF42 (36) |
| High Drop (Drop 3) AF13 (14) AF23 (22) AF33 (30) AF43 (38) |
+-------------------------------------------------------------------------+
(Calculation example for Interactive Video: Class 4 with Low Drop = or AF41).
4. Class Selector (CS - RFC 2474)
To ensure complete backward compatibility with legacy IP Precedence hardware, the DiffServ standard defines eight Class Selector code points of the form xxx000 (where bits 3 to 5 are zero). The DSCP value is simply :
- CS0: DSCP 0 (IPP 0 - Best Effort)
- CS1: DSCP 8 (IPP 1 - Scavenger)
- CS2: DSCP 16 (IPP 2 - Network Management)
- CS3: DSCP 24 (IPP 3 - Call Control Signaling)
- CS4: DSCP 32 (IPP 4 - Real-Time Interactive video, such as TelePresence)
- CS5: DSCP 40 (IPP 5 - Broadcast Video)
- CS6: DSCP 48 (IPP 6 - Network Routing Protocols: OSPF/BGP)
- CS7: DSCP 56 (IPP 7 - Critical Network Control)
4. Cisco Collaboration Baseline Marking Standards
Cisco publishes baseline QoS marking standards to ensure deterministic media delivery across all enterprise collaboration hardware and software platforms:
| Traffic Classification | Protocol / Application | Layer 2 CoS | Layer 3 DSCP | PHB Designation |
|---|---|---|---|---|
| Voice Media | RTP (Audio Streams) | CoS 5 | DSCP 46 | Expedited Forwarding (EF) |
| Interactive Video | RTP (Two-Way Video / Webex) | CoS 4 | DSCP 34 | Assured Forwarding 41 (AF41) |
| Real-Time Interactive Video | TelePresence | CoS 4 | DSCP 32 | Class Selector 4 (CS4) |
| Broadcast Video | IP video surveillance, digital signage | CoS 5 | DSCP 40 | Class Selector 5 (CS5) |
| Call Control Signaling | SIP, H.323, SCCP, MGCP | CoS 3 | DSCP 24 | Class Selector 3 (CS3)* |
| Network Control | OSPF, BGP, RIP, EIGRP | CoS 6 | DSCP 48 | Class Selector 6 (CS6) |
| Best Effort Data | HTTP, FTP, General Data | CoS 0 | DSCP 0 | Default Forwarding (DF) |
*(Note: Historical legacy implementations marked voice signaling as AF31 / DSCP 26. Cisco modern QoS baseline architecture marks call control signaling as CS3 / DSCP 24).
5. QoS Trust Boundaries & Cisco IP Phone Integration
A QoS Trust Boundary is the physical or logical perimeter in a network topology where ingress QoS markings are accepted as valid (trusted) versus where markings are rejected, stripped, or rewritten to zero (untrusted).
+-------------------------------------------------------------------------+
| QoS TRUST BOUNDARY MODELS |
| |
| 1. UNTRUSTED BOUNDARY: |
| [Workstation / PC] ---> (Port Re-marks to DSCP 0) ---> [Switch] |
| |
| 2. TRUSTED BOUNDARY: |
| [Trusted Voice Gateway / Server] ---> (Ingress DSCP Preserved) |
| |
| 3. CONDITIONALLY TRUSTED BOUNDARY (CISCO IP PHONE): |
| +-------------+ |
| | Workstation | (Untrusted Data) |
| +------+------+ |
| | Re-marked to CoS 0 / DSCP 0 |
| +------v------+ |
| | Cisco Phone | (Tags Voice as CoS 5 / EF, Signaling as CoS 3 / CS3)|
| +------+------+ |
| | 802.1Q Auxiliary Trunk (Voice VLAN + Data VLAN) |
| +------v------+ |
| | Access Port | (Switch trusts Phone markings via CDP / LLDP) |
| +-------------+ |
+-------------------------------------------------------------------------+
The Untrusted Access Problem
If an access switchport is configured to blindly trust all incoming DSCP markings (trust dscp), any standard desktop or rogue user could configure their network interface card to mark peer-to-peer file downloads or torrent traffic as DSCP EF (46). That traffic would then be injected into the hardware Priority Queue across the corporate WAN, causing catastrophic starvation of actual voice calls. Therefore, workstation access ports must be untrusted.
Cisco IP Phone 3-Port Internal Switch
To eliminate the expense of running separate physical Ethernet drops for IP phones and user workstations, Cisco IP phones incorporate an internal 3-port 10/100/1000 switch:
- Internal port: Connects to the internal phone hardware (DSP, keypad, screen, operating system). Generates voice media tagged with CoS 5 / DSCP EF and signaling tagged with CoS 3 / DSCP CS3.
- PC (access) port: Connects to the user's laptop or workstation. Traffic from the PC enters the phone untagged.
- Network port: Connects to the upstream Cisco Catalyst access switch. Sends an 802.1Q frame containing both the tagged Voice VLAN and untagged (or access-tagged) Data VLAN.
Conditional Trust Mechanism
The switchport utilizes Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP) to detect the presence of an authentic Cisco IP Phone:
- If a valid Cisco IP Phone is detected via CDP/LLDP, the switchport activates Conditional Trust. It trusts the CoS/DSCP markings arriving within the Voice VLAN from the phone hardware.
- Concurrently, the switch or phone re-marks all frames originating from the attached PC on the data port to CoS 0 / DSCP 0 (Best Effort).
- If an attacker unplugs the phone and connects a laptop directly into the wall jack, CDP/LLDP discovery fails. The switchport immediately revokes trust and re-marks all incoming traffic on the port to DSCP 0.
Switchport Configuration Example
! Modern Cisco IOS XE Conditional Trust Access Port Configuration
interface GigabitEthernet1/0/10
description Access Port with Cisco IP Phone and PC Workstation
switchport mode access
switchport access vlan 10
switchport voice vlan 150
trust device cisco-phone
auto qos voip cisco-phone
spanning-tree portfast
spanning-tree bpduguard enable
6. QoS for Voice and Video over Wireless (Blueprint 6.2)
Wi-Fi is a shared, half-duplex medium: clients and access points contend for airtime with CSMA/CA, so wired priority queuing alone cannot protect voice once packets reach the radio. IEEE 802.11e, certified as Wi-Fi Multimedia (WMM), gives each frame an 802.11 User Priority (UP) and four access categories with different contention settings (shorter waits and smaller backoff windows for voice):
| WMM access category | 802.11 User Priority | Typical traffic |
|---|---|---|
| AC_VO (voice) | 6, 7 | Voice media |
| AC_VI (video) | 4, 5 | Interactive video |
| AC_BE (best effort) | 0, 3 | Ordinary data |
| AC_BK (background) | 1, 2 | Bulk and scavenger traffic |
Mapping between DSCP and UP: RFC 8325 maps EF (46) to UP 6 (voice), AF4x and CS4 to UP 4 (video), and best-effort traffic to UP 0. It places CS3 in UP 4 and CS5 in UP 5, so Cisco's CS3 call signaling rides in the video access category.
Cisco wireless settings:
- A WLAN's QoS profile sets the highest priority its traffic can receive: Platinum for voice, Gold for video, Silver for best effort, and Bronze for background. Voice SSIDs use Platinum with WMM enabled.
- Upstream, the client marks its own frames (UP and DSCP). Downstream, the access point maps the DSCP of the wired packet to a UP for the radio. Between the access point and the controller, the CAPWAP outer header carries a DSCP derived from the inner marking, capped by the WLAN's profile.
- Wireless call admission control limits how many voice calls an access point radio accepts, because airtime, not wired bandwidth, is the scarce resource; admitting too many calls degrades every call on that radio.
Design consequences: Voice over Wi-Fi needs the same end-to-end markings as the wired network, an enterprise-grade RF design (coverage overlap for roaming, low channel utilization), and fast roaming support so calls survive moves between access points.
A network engineer needs to determine the decimal Differentiated Services Code Point (DSCP) value for an interactive video stream marked as Assured Forwarding Class 4 with Medium Drop Precedence (AF42). What is the correct decimal DSCP value and its 6-bit binary representation?
DSCP 34 (binary 100010)
DSCP 42 (binary 101010)
DSCP 36 (binary 100100)
DSCP 38 (binary 100110)
According to Cisco collaboration QoS architecture and baseline marking guidelines, what are the recommended Layer 3 DSCP markings for voice media (RTP) and collaboration call control signaling (such as SIP), respectively?
Voice Media = DSCP EF (46); Collaboration Call Signaling = DSCP CS3 (24)
Voice Media = DSCP AF41 (34); Collaboration Call Signaling = DSCP EF (46)
Voice Media = DSCP CS3 (24); Collaboration Call Signaling = DSCP CS0 (0)
Voice Media = DSCP CS5 (40); Collaboration Call Signaling = DSCP AF11 (10)
A network engineer configures an access switchport connected to a Cisco IP Phone with an attached PC. What occurs if the administrator configures 'trust device cisco-phone' and the user unplugs the phone and connects their laptop directly to the switchport?
The switch automatically routes the laptop traffic into the voice VLAN with full CoS 5 priority.
When CDP or LLDP no longer detects a Cisco phone, the switch stops trusting the port and re-marks ingress traffic to DSCP 0.
The switch puts the port into an error-disabled (err-disable) state due to a QoS trust violation.
The switch continues to trust incoming DSCP markings because port security retains the MAC address of the Cisco IP Phone.
Sections you finish are checked off in the contents.