Cisco class-map not matching anything

In a lab network, I'm trying to learn why a class-map is not matching any traffic.  I have two Cisco routers with a serial interface that works well in passing all traffic, but I'm trying to get MQC set up for QoS.
class-map match-any VOICE
 match  dscp ef
class-map match-any CALL-SIGNALING
 match  dscp af41
 match  dscp cs3
!
!
policy-map WAN-EDGE
 class VOICE
  priority percent 30
 class CALL-SIGNALING
  bandwidth 128
 class class-default
  fair-queue

Open in new window

It is applied to the serial interface on output:
interface Serial0/2/0
 ip address 192.168.203.1 255.255.255.0
 service-policy output WAN-EDGE

Open in new window

When I send DSCP 46 tagged traffic through the interface, it all goes to the default queue:
Honolulu#show policy-map interface s0/2/0
 Serial0/2/0

  Service-policy output: WAN-EDGE

    Class-map: VOICE (match-any)
      0 packets, 0 bytes
      5 minute offered rate 0 bps, drop rate 0 bps
      Match:  dscp ef (46)
        0 packets, 0 bytes
        5 minute rate 0 bps
      Queueing
        Strict Priority
        Output Queue: Conversation 264
        Bandwidth 30 (%)
        Bandwidth 463 (kbps) Burst 11575 (Bytes)
        (pkts matched/bytes matched) 0/0
        (total drops/bytes drops) 0/0

    Class-map: CALL-SIGNALING (match-any)
      0 packets, 0 bytes
      5 minute offered rate 0 bps, drop rate 0 bps
      Match:  dscp af41 (34)
        0 packets, 0 bytes
        5 minute rate 0 bps
      Match:  dscp cs3 (24)
        0 packets, 0 bytes
        5 minute rate 0 bps
      Queueing
        Output Queue: Conversation 265
        Bandwidth 128 (kbps) Max Threshold 64 (packets)
        (pkts matched/bytes matched) 0/0
        (depth/total drops/no-buffer drops) 0/0/0

    Class-map: class-default (match-any)
      19955 packets, 4077842 bytes
      5 minute offered rate 82000 bps, drop rate 0 bps
      Match: any
      Queueing
        Flow Based Fair Queueing
        Maximum Number of Hashed Queues 256
        (total queued/total drops/no-buffer drops) 49/852/0

Open in new window

I have verified with a sniffer that the packets are properly DSCP tagged, but I don't know why they are not being put into that queue.
Tim TitusCTOAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Ken BooneNetwork ConsultantCommented:
So when you say you know they are tagged, tell me where the source device is connected that is generated DSCP EF packets.  Then what is it connected to, where is the router connected, are there multiple switches, etc..  and what port did you run the sniffer against.  I'm trying to determine if you have switches that are re-writing the DSCP value in your path.

Your config looks fine.
0
Tim TitusCTOAuthor Commented:
If I send DSCP tagged packets from my PC to a PC on the other side of the network, I can verify that DSCP tagged packets are coming out of my PC via wireshark, and I can verify that the packets that reach the far-end are DSCP tagged as well.  That proves that DSCP is making it through to the other side (and back for that matter).

To answer your specific question, I am going through 2 layer-2 switches before I hit this router and neither switches have any configuration that would strip DSCP.

I just don't know why they are not being put into the proper class-map.
0
Ken BooneNetwork ConsultantCommented:
Ok just want to make sure.  Cisco switches if not set up properly to handle those DSCP values will remark them by default that is why I was asking.  But if you are seeing the packets on the far side still with the DSCP value set correctly then I would say you are correct.

So that leaves me to believe that you might have an IOS problem.  I have seen class maps not match before just do to an IOS problem.  I would upgrade your IOS and then see where its at.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

JustInCaseCommented:
By default switch do not trust DSCP markings and will overwrite DSCP to default value, you need to configure switch to trust end device.
Try to configure under interface
auto qos trust
0
Tim TitusCTOAuthor Commented:
I've requested that this question be closed as follows:

Accepted answer: 0 points for ttitus's comment #a41270604

for the following reason:

It's still  weird that I'm getting DSCP tagging through to the far side, but I added an additional "match" condition to match the IP address of my computer and it started to match based on IP address, thus proving that the class-map is now working properly on the router.

I still have no idea why the match on dscp ef is not working, but you helped lead me to the solution.  Thanks!
0
Tim TitusCTOAuthor Commented:
FYI: The switches in my environment are HP switches that do not strip DSCP.
0
Ken BooneNetwork ConsultantCommented:
So that indicates that it is most likely an IOS issue which was one of my recommended solutions to solve the problem you started with which was dealing with matching the DSCP value.    I did spend some time looking at this with you to try and help you.  When you close a case where someone spent their time trying to assist you with good suggestions, the least you can do is award some points.  

In order to get your original class map working properly I would still recommend upgrading the IOS.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Tim TitusCTOAuthor Commented:
Tried to award points earlier, but the system did not seem to do this.  I want to give you all the points.  Let's try this again.
0
Tim TitusCTOAuthor Commented:
It seems that Experts-Exchange is having some problems.  If they don't award you the points, let me know and I'll open a case with their support.  You certainly earned the points!  Thank you!
0
Ken BooneNetwork ConsultantCommented:
Thank you!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Voice Over IP

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.