Does Firewall DSCP work with NAT Offloading?

Your qosify configurations would need to set DSCP using the + convention (e.g. +af41, +video) so that qosify only overrides the DSCP if it is still CS0.

With offloading, only the first packet of a connection will traverse the firewall rules, so the remaining packets won’t get marked. You can use methods used with the script below to use ctinfo to make it work however,

2 Likes