Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN ToS Tagging

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jdp0418
      last edited by

      Hi all,
      Question about the check box for this option:
        "Set the TOS IP header value of tunnel packets to match the encapsulated packet value."

      Does that ToS value then make it to the outside of the OpenVPN encapsulation such that I could build a QoS policy matching the ToS tag?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Yes. If the inner packet (for example, VoIP inside the VPN) has TOS/DSCP set, using that option will copy the TOS bits to the outer VPN packet where it could be matched for QoS anywhere along the path.

        There is some slight information disclosure (someone could infer that it's VoIP or video from the TOS header) so it's off by default

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          jdp0418
          last edited by

          Thanks Jim.  I've seen many a bandwidth provider (Comcast primarily) actually strip tagging once the packet reaches their network, so this would simply accomplish ensuring that the PFSense is forwarding VOIP packets before others, whether inside a tunnel or not.  Actually, this is good news for VPN tunnel QOS, as I've seen several postings on here arguing that QOS within a tunnel doesn't work.  While that is technically correct, this feature at least allows for QOS on specific traffic, whether its inside a tunnel or not.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.