View Single Post
  #1 (permalink)  
Old 2007-02-15
pbkirk pbkirk is offline
Junior Member
 
Join Date: 2007-02-15
Posts: 1
Rep Power: 0
pbkirk has an average reputation (10+)
Default NGX R60 QoS, IPSEC and ClusterXL - FTP DiffServ Marking

I'm having problems getting CP SPLAT to properly mark DiffServ for FTP traffic over an encrypted link. The VPN community includes a remote Gateway's inside LAN segment and central site cluster inside LAN segment.

I've added the SPLAT and FW hotfixes to all gateways/cluster members and Smartcenter Server, performed some tests, and here's what I found. I can get a single Gateway to mark FTP packets with Diffserv on a traffic flow between a host (on remote Gateway's inside LAN segment) and central site server (on inside cluster LAN segment), but the cluster will not mark the packets. It doesn't matter what direction the connection and transfer occur in (RMT to CS or vice versa), no packets sourced from central site are ever marked. It's almost as if the QoS Diffserv should be applied to the physical interfaces instead of the Cluster interface IP, but the object's topology edit won't let you do that (there's not a QoS tab for the physical interfaces, just for the cluster interface). Has anyone else had this problem?
Reply With Quote