SRX Services Gateway
SRX Services Gateway

Prioritize voice traffic over other on the same IPSec VPN tunnel

‎01-05-2018 01:28 AM

Hi,

Is there a way to prioritize voice traffic over the rest of the traffic on a route based IPSec VPN tunnel for SRX firewalls?

Where can i find some configuration examples and some documentation related to that?

Thank you,

tcp

6 REPLIES 6
SRX Services Gateway

Re: Prioritize voice traffic over other on the same IPSec VPN tunnel

‎01-05-2018 01:40 AM

Which version of code are you running? There have been some enhancements in the recent versions on traffic prioritization over IPSEC. 

 

Anand

SRX Services Gateway

Re: Prioritize voice traffic over other on the same IPSec VPN tunnel

‎01-05-2018 02:51 AM

Hi,

I am using JUNOS 15.1X49-D40.6, but i can do an upgrade if needed.

Regards,

tcp

SRX Services Gateway

Re: Prioritize voice traffic over other on the same IPSec VPN tunnel

‎01-05-2018 02:59 AM
Yes. You would have to. On branch platforms support for COS on st0 interfaces begins from 15.1X49-D60.

Anand
SRX Services Gateway

Re: Prioritize voice traffic over other on the same IPSec VPN tunnel

‎01-05-2018 03:25 AM

Hi,

Do you know where can i get some examples on how to implement it?

Regards,

tcp

SRX Services Gateway

Re: Prioritize voice traffic over other on the same IPSec VPN tunnel

‎01-05-2018 11:00 AM

Hi Folks,

Just my 2 cents on this…

 

Understanding CoS Support on st0 Interfaces

 

Starting with Junos OS Release 15.1X49-D60 and Junos OS Release 17.3R1, class of service (CoS) features such as classifier, policer, queuing, scheduling, shaping, rewriting markers, and virtual channels can now be configured on the secure tunnel interface (st0) for point-to-point VPNs.

 

The st0 tunnel interface is an internal interface that can be used by route-based VPNs to route cleartext traffics to an IPsec VPN tunnel. The following CoS features are supported on the st0 interface on all available SRX Series devices and vSRX2.0:

 

Classifiers

Policers

Queuing, scheduling, and shaping

Rewrite markers

Virtual channels

     

Note: Starting with Junos OS Release 15.1X49-D70 and Junos OS Release 17.3R1, support for queuing, scheduling, shaping, and virtual channels is added to the st0 interface for SRX5400, SRX5600, and SRX5800 devices. Support for all the listed CoS features is added for the st0 interface for SRX1500, SRX4100, and SRX4200 devices. Starting with Junos OS Release 17.4R1, support for listed CoS features is added for the st0 interface for SRX4600 devices.

 

Limitations of CoS support on VPN st0 interfaces

The following limitations apply to CoS support on VPN st0 interfaces:

 

The maximum number for software queues is 2048. If the number of st0 interfaces exceeds 2048, not enough software queues can be created for all the st0 interfaces.

Only route-based VPNs can apply CoS features on st0 interfaces. Table 1 describes the st0 CoS feature support for different types of VPNs.

 

https://www.juniper.net/documentation/en_US/junos/topics/concept/understanding-cos-support-on-st0.ht...

 

-Python JNCIE 3X [SP|DC|ENT] JNCIP-SEC JNCDS 3X [ WAN | DC|SEC] JNCIS-Cloud JNCIS-DevOps CCIP ITIL
#Please mark my solution as accepted if it helped, Kudos are appreciated as well.
SRX Services Gateway

Re: Prioritize voice traffic over other on the same IPSec VPN tunnel

‎01-08-2018 02:18 AM

Hi,

Is CoS for st0 interfaces available for lower end devices such SRX300 and SRX550 too or only for the mentioned devices? 

Regards,

tcp