<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco mls qos trust dscp traffic through Checkpoint R77.30 Gaia  firewalls in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cisco-mls-qos-trust-dscp-traffic-through-Checkpoint-R77-30-Gaia/m-p/25384#M5134</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;Hello ALL,&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;Does Checkpoint Gaia R77.30 appliances running only Firewall and ClusterXL modules (NO QOS) allow Cisco mls qos trust dscp traffic to traverse through the firewall when two Cisco Routers are connecting through the firewall using QOS?&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;The Router A (Source) is trying to apply a QOS profile to traffic going through the firewall to Router B on the other side of the firewall but the QOS profile is not being seen on Router B.&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&amp;nbsp;Router A is using static routes towards the firewall while the Firewall and Router B are running ospf.&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;So will the firewall drop such traffic, &amp;nbsp;or just past it on by default proving normal traffic rules are in place on the firewall? &amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;Plus how can I check if any such drops for Cisco mls qos trust dscp on the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Jan 2018 13:31:00 GMT</pubDate>
    <dc:creator>Olu_Fagbohun</dc:creator>
    <dc:date>2018-01-26T13:31:00Z</dc:date>
    <item>
      <title>Cisco mls qos trust dscp traffic through Checkpoint R77.30 Gaia  firewalls</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-mls-qos-trust-dscp-traffic-through-Checkpoint-R77-30-Gaia/m-p/25384#M5134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;Hello ALL,&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;Does Checkpoint Gaia R77.30 appliances running only Firewall and ClusterXL modules (NO QOS) allow Cisco mls qos trust dscp traffic to traverse through the firewall when two Cisco Routers are connecting through the firewall using QOS?&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;The Router A (Source) is trying to apply a QOS profile to traffic going through the firewall to Router B on the other side of the firewall but the QOS profile is not being seen on Router B.&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&amp;nbsp;Router A is using static routes towards the firewall while the Firewall and Router B are running ospf.&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;So will the firewall drop such traffic, &amp;nbsp;or just past it on by default proving normal traffic rules are in place on the firewall? &amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;Plus how can I check if any such drops for Cisco mls qos trust dscp on the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jan 2018 13:31:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-mls-qos-trust-dscp-traffic-through-Checkpoint-R77-30-Gaia/m-p/25384#M5134</guid>
      <dc:creator>Olu_Fagbohun</dc:creator>
      <dc:date>2018-01-26T13:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco mls qos trust dscp traffic through Checkpoint R77.30 Gaia  firewalls</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-mls-qos-trust-dscp-traffic-through-Checkpoint-R77-30-Gaia/m-p/25385#M5135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume all the Cisco is doing in this case is tagging the relevant packets with DSCP tags.&lt;/P&gt;&lt;P&gt;Generally speaking, we should leave those tags alone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said, there were some situations in the past where we would strip the DSCP tags.&lt;/P&gt;&lt;P&gt;What I would do to troubleshoot this is to review the relevant traffic as it traverses the gateway, reviewing the DSCP tags as they are received by the gateway and pass through it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the Cisco is doing something else to establish a QoS profile, that traffic would have to be allowed separately through the Security Gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Jan 2018 05:49:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-mls-qos-trust-dscp-traffic-through-Checkpoint-R77-30-Gaia/m-p/25385#M5135</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-27T05:49:12Z</dc:date>
    </item>
  </channel>
</rss>

