networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 9 posts ] 
Author Message
PostPosted: Wed Apr 18, 2012 8:57 am 
Offline
Member
Member
User avatar

Joined: Mon Sep 06, 2010 1:55 pm
Posts: 238
Location: USA
Certs: CCNA, Sec+, Net+, A+
Who's skilled enough to know the reason for this symptom...

My workplace has a UC-540 attached to a cable modem, attached to the world wide web.

When we make VOIP outbound calls through the standard ISP, there is no auditory packet loss sympton; however, when we make calls to out sister branch through our VPN, we experience auditory packet loss symptoms.

I would think the VPN should only be affecting the encapsulation of the data. To my understanding the VPN packets and non-vpn packets all hit the router at the same time, and transport over the web in the same manner. Why would there be packet loss over only the VPN???

--Regarding QoS, if a standard layer 3 device receives a VOIP packet encapsulated in a VPN, do the QoS bits in the VOIP packet get acknowledged, or are they hidden by the VPN encapsulation?

:thankyou: :bowdown:


Top
 Profile  
 
PostPosted: Wed Apr 18, 2012 9:10 am 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Thu Jun 23, 2011 3:17 pm
Posts: 579
Certs: CCNA, CCNA Security
They are hidden by the vpn.
There is a command that makes the router maintains it but not likely to be cause your problem.
How is the traffic normally? Not just voice over the vpn?

_________________
Networking is much like making love to a beautiful woman
Slide your equipment in to the rack, Stick your plug in the socket, and if you have done it right at the end everyone is happy


Top
 Profile  
 
PostPosted: Wed Apr 18, 2012 11:32 am 
Offline
CCIE #38070
CCIE #38070
User avatar

Joined: Wed Jun 18, 2008 7:49 am
Posts: 12433
Location: London, UK
Certs: CCIE ,CC-NP/IP, JNCIP-SP, JNCIS-ENT, BC-/SPNE/NP
You should be able to configure your device to put the original packets dscp marking into the tunnel header packets, preserving that marking.

Are you sure your firewall/vpn device (on both sides) has enough CPU to be able to encapsulate, encrypt and decrpyt those millions of tiny voice packets? If not, that could be your problem.

_________________
www.mellowd.co.uk/ccie/


Top
 Profile  
 
PostPosted: Wed Apr 18, 2012 1:36 pm 
Offline
Member
Member
User avatar

Joined: Mon Sep 06, 2010 1:55 pm
Posts: 238
Location: USA
Certs: CCNA, Sec+, Net+, A+
Teebor wrote:
They are hidden by the vpn.
There is a command that makes the router maintains it but not likely to be cause your problem.
How is the traffic normally? Not just voice over the vpn?


The symptom is that packet loss is experienced only over the VPN, not the un-encapsulated network; so in my thinking, the encapsulated unread QoS bits would be a prime culprit for this symptom.

?? Prey tell, what is that command that enables the QoS bits to be exposed throughout the encapsulation??


Top
 Profile  
 
PostPosted: Wed Apr 18, 2012 1:40 pm 
Offline
Member
Member
User avatar

Joined: Mon Sep 06, 2010 1:55 pm
Posts: 238
Location: USA
Certs: CCNA, Sec+, Net+, A+
mellowd wrote:
You should be able to configure your device to put the original packets dscp marking into the tunnel header packets, preserving that marking.

Are you sure your firewall/vpn device (on both sides) has enough CPU to be able to encapsulate, encrypt and decrpyt those millions of tiny voice packets? If not, that could be your problem.


Is the CPU adequate? I surely dont know. The device is a standard UC540. How can i tell if the CPU can handle the VPN encapsulation in an acceptable speedy fashion?

How can I configure my device to preserver the dscp marking at the tunnel header packets?

:thankyou:


Top
 Profile  
 
PostPosted: Sat Apr 28, 2012 10:14 pm 
Offline
Post Whore
Post Whore

Joined: Sat Jun 07, 2008 11:06 am
Posts: 2553
Location: Grand Rapids, MI
Certs: CCNP, CCDP
IPP/DSCP QoS tags are automatically copied from the unencrypted packet to the encrypted one. You don't need to do anything special to do this.

Unless you are classifying packets at the same time (for example, if you're using 'match protocol rtp'). The classification process will not see the original IP headers, so it doesn't know how to prioritize them. In that case, you do need 'qos pre-classify'.


Top
 Profile  
 
PostPosted: Sun Apr 29, 2012 12:28 am 
Offline
New Member
New Member

Joined: Thu Apr 26, 2012 1:19 pm
Posts: 27
Certs: CCNA / CCNA VOICE
what device is at the sister branch terminating your vpn from the uc540? another uc500?

not all equipment supports qos on ipsec encrypted traffic

also how do you know its packet loss and not something else - what are you seeing exactly?


Top
 Profile  
 
PostPosted: Sun Apr 29, 2012 2:24 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Wed Jun 17, 2009 11:28 am
Posts: 1579
Location: Longford Ireland
Certs: BSc computer network administration, CCNP, MCSE
mrome74 wrote:
mellowd wrote:
You should be able to configure your device to put the original packets dscp marking into the tunnel header packets, preserving that marking.

Are you sure your firewall/vpn device (on both sides) has enough CPU to be able to encapsulate, encrypt and decrpyt those millions of tiny voice packets? If not, that could be your problem.


Is the CPU adequate? I surely dont know. The device is a standard UC540. How can i tell if the CPU can handle the VPN encapsulation in an acceptable speedy fashion?

How can I configure my device to preserver the dscp marking at the tunnel header packets?

:thankyou:


When you next run the VPN run sh proc cpu then sh proc cpu hist and these will tell you how your device is handling the encryption process.
When you run the first show command look for the encryption process and see what it's running at.

_________________
Good Luck,

David


Top
 Profile  
 
PostPosted: Mon May 07, 2012 10:17 am 
Offline
Member
Member
User avatar

Joined: Mon Sep 06, 2010 1:55 pm
Posts: 238
Location: USA
Certs: CCNA, Sec+, Net+, A+
Thx for your help!!! :thankyou:


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group