DSCP value not propagated in the packet when using Trusted mode of QoS
search cancel

DSCP value not propagated in the packet when using Trusted mode of QoS

book

Article ID: 371944

calendar_today

Updated On:

Products

VMware NSX VMware NSX-T Data Center

Issue/Introduction

  • The QoS profile when configured in Trusted mode and attached to the segment, the configured DSCP value is not present in the packet, due to which the QoS traffic prioritization and shaping could not be done.
  • When selecting the Trusted mode in DSCP settings, the inner header DSCP value is applied to the outer IP header for IP/IPv6 traffic. 
    Whereas, in the case of Untrusted mode, the DSCP value of the outbound IP header is set to the configured value irrespective of the inner packet type for the logical port.
  • It has been observed that the DSCP settings are not applied to the packets in Trusted mode, and while looking at the packet captures on the uplink interface of the ESXi host, the DSCP value remains 0:


  • QoS configuration on NSX-T:

Environment

VMware NSX-T Data Center

VMware NSX

Cause

This is a known issue due to one of the flow actions not being initialized properly.

Resolution

This is fixed on VMware NSX 4.1.1 Release and above

Workaround: Change the DSCP mode to "Untrusted" for the associated QoS profile