Hi Iris, strongSwan is able to set up multiple concurrent IPsec SAs between two hosts, the Linux netfilter kernel module is able to filter traffic according to DSCP marking but the Linux kernel currently unfortunately is not able to assign plaintext traffic according to their DSCP marking to individual IPsec SAs. This would require some non-trivial changes in the Linux IPsec stack. Although this is not primarily a strongSwan issue we would be interested in implementing this QoS feature in the kernel if someone would be willing to sponsor this endeavour.
Best regards Andreas Iris Su wrote: > Hi, > > Does anyone know if strongswan support DSCP Marking? > If the answer is Yes, can we configure it? (enable or disable DSCP) > > BR, > Iris ====================================================================== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland) ===========================================================[ITA-HSR]== _______________________________________________ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users