Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[ScreenOS] How to set the DSCP value for each route-based VPN



Article ID: KB11161 KB Last Updated: 14 Mar 2013Version: 5.0

This article provides information on how to configure Differentiated Services Code Point (DSCP) Marking for the ESP-tunnel packet.


Is DSCP supported with route-based VPNs?



In ScreenOS 6.1, the DSCP value for each route-based VPN can be configured on the firewall. Prior to ScreenOS 6.1, DSCP marking was supported only via policies.

To enable this new feature, use the set vpn <vpn-name> dscp-mark <dscp-value> command, in which <dscp-value> is between 0 and 63.

For example:

To enable the DSCP mark for traffic that is going through the VPN test, use the following command:

set vpn test dscp-mark 10

To verify the configuration, use the following command:

ssg20-> get vpn test

DSCP-mark: enabled, value: 10

Related Links

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search