IPsec currently makes QoS for tunnels somewhat difficult, as
RFC 2401 requires copying the DSCP from the inner header
to the outer header on tunnel ingress, and discarding it at tunnel egress, even if it's been changed. This is
overly severe, and I believe/hope that it will be made more
flexible in the new version of RFC 2401.
Lars -- Lars Eggert <larse@xxxxxxx> Information Sciences Institute http://www.isi.edu/larse/ University of Southern California
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature