3

I have to validate whether my router's QOS policies are working correctly.I have come up with an approach to tag the packets with DSCP values using IPTABLES.

Can anyone confirm whether my approach is correct?If not please provide your help to correct the same. enter image description here

IPtables rule enter image description here

# Mark packets based on the originating port and other requirements mentioned in the table

iptables -t mangle -A OUTPUT -p IGMP -m udp --sport 5051 -j DSCP --set-dscp-class cs5 iptables -t mangle -A OUTPUT -p IGMP -m IGMP --sport 5052 -j DSCP --set-dscp-class cs5 iptables -t mangle -A OUTPUT -p udp -m udp --sport 5053 -j DSCP --set-dscp-class cs5 iptables -t mangle -A OUTPUT -p udp -m udp -d xxx.123.219.132/32 --dport 5054 -j DSCP --set-dscp-class cs2 iptables -t mangle -A OUTPUT -p udp -m udp -d xxx.123.219.132/32 --dport 5055 -j DSCP --set-dscp-class cs2 iptables -t mangle -A OUTPUT -p udp -m udp --sport 5056 --dport 123 -j DSCP --set-dscp-class cs2 iptables -t mangle -A OUTPUT -p udp -m udp --sport 5057 --dport 67:68 -j DSCP --set-dscp-class cs2 iptables -t mangle -A OUTPUT -p udp -m udp --sport 5058 --dport 53 -j DSCP --set-dscp-class cs2

Renold Singh
  • 336
  • 2
  • 3
  • 13

0 Answers0