Solved

Cisco 3560 Switch DSCP Marking for RDP

Posted on 2013-01-03
4
1,251 Views
Last Modified: 2013-01-07
I would like to mark my RDP traffic to 2 particular host as DSCP AF31. However, my config does not seem to work. Anyone can help troubleshoot?

ip access-list extended CLASSIFY-RDPServers
 permit tcp host 192.168.20.80 any eq 3389
 permit tcp host 192.168.20.8 any eq 3389
 permit tcp any host 192.168.20.8 eq 3389
 permit tcp any host 192.168.20.80 eq 3389

class-map match-any CLASSIFY-RDPServers
 match access-group name CLASSIFY-RDPServers
class-map match-all AutoQoS-VoIP-RTP-Trust
 match ip dscp ef
class-map match-all AutoQoS-VoIP-Control-Trust
 match ip dscp cs3  af31
class-map match-all CLASSIFY-Video
 match ip dscp af41

policy-map AutoQoS-Police-CiscoPhone
 class AutoQoS-VoIP-RTP-Trust
  set dscp ef
  police 320000 8000 exceed-action policed-dscp-transmit
 class AutoQoS-VoIP-Control-Trust
  set dscp cs3
  police 32000 8000 exceed-action policed-dscp-transmit
 class CLASSIFY-Video
  set dscp af41
  police 2000000 8000 exceed-action policed-dscp-transmit
 class CLASSIFY-RDPServers
  set dscp af31

Open in new window


From packet captures, I can see that the policy-map works for ef, af41 traffic. But RDP traffic is not marked as af31.
0
Comment
Question by:frukeus
4 Comments
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 166 total points
ID: 38743570
Are you seeing any hits against the ACL  "CLASSIFY-RDPServers"?
0
 
LVL 10

Assisted Solution

by:koudry
koudry earned 167 total points
ID: 38745854
I think you need to test the ACL first, by attaching it to the interface, to make sure it is working. If it is not working, try simple IP, e.g.

!
access-list 101 permit ip host 192.168.20.80 any
!
interface x
ip access-group 101 in
!

If this works, use this ACL on a test class map and policy and test again separately away from the other classes.
0
 
LVL 10

Accepted Solution

by:
mat1458 earned 167 total points
ID: 38748275
Is the RDP traffic using the interfaces on which you have set the service policy? Is RDP using the standard ports on the two systems?

You config looks pretty good, the stuff you have posted should do what you intend to. But for completeness reasons: can you please post the other access lists as well? There might be something in them that erroneusly marks the RDP traffic with some other tag.

If you can post it the pcap file would help as well.
0
 
LVL 1

Author Closing Comment

by:frukeus
ID: 38753228
Yes, the problem was with the ACL.
It should be
10 permit tcp host 192.168.48.80 eq 3389 any
20 permit tcp host 192.168.48.8 eq 3389 any

to capture the RDP traffic instead of
10 permit tcp host 192.168.48.80 any eq 3389
20 permit tcp host 192.168.48.8 any eq 3389
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cisco 2960 PACL 9 37
MPLS Network Question 2 35
Quick cusco 2091 setup 5 22
Move configuration from Cisco 3560 to 3750X 6 18
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Skype is a P2P (Peer to Peer) instant messaging and VOIP (Voice over IP) service – as well as a whole lot more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now