Prioritize and Preserve Host Outbound Traffic
Learn how to prioritze the host outbound traffic on your MX204, MX301, MX304, MX10004, or MX10008 router.
Host-generated traffic originates at multiple levels:
- Control and management traffic generated by the Routing Engine
- Control traffic generated by line card CPUs for distributed protocols such as LACP and BFD
- Control traffic generated by the PFE or ASIC, such as inline BFD
Configure a dedicated queue for host-generated traffic. This traffic shares egress resources with transit traffic on physical interfaces. Prioritize host-generated traffic to ensure reliable operation under all conditions.
Global Configuration
Host-generated traffic is typically placed in a strict-high queue to prevent starvation. The configuration of queue parameters is outside the scope of this section; we will assume that host-generated traffic is queued in queue "7", mapped to the forwarding class "HOST_OUTBOUND".
The simplest way to assign all host-generated traffic to a queue is to use the following global command:
set class-of-service host-outbound-traffic forwarding-class HOST_OUTBOUND
This overrides the default mapping (see: Class of Service User Guide for Routers) for all host-generated traffic, including distributed and inline control plane traffic.
You can also remark IP-based host-generated traffic with a specific DSCP code point using the optional parameter below:
set class-of-service host-outbound-traffic forwarding-class HOST_OUTBOUND dscp-code-point cs6
Fine-grained Configuration
Use a firewall filter to classify host-generated IP traffic from the Routing Engine with greater granularity. This method applies only to Routing Engine–generated traffic and does not apply to distributed control plane traffic. For example, use this method to separate management traffic from other control traffic.
Configure a firewall filter for the inet and/or inet6
family and apply it to the loopback interface (lo0.0) in the output
direction. In the following example, SSH traffic uses the MANAGEMENT
forwarding class instead of HOST_OUTBOUND. All other control plane
traffic uses the HOST_OUTBOUND forwarding class based on the global
configuration.
set class-of-service host-outbound-traffic forwarding-class HOST_OUTBOUND set firewall family inet filter RE-OUT term 1 from protocol tcp set firewall family inet filter RE-OUT term 1 from port ssh set firewall family inet filter RE-OUT term 1 then forwarding-class MANAGEMENT set firewall family inet filter RE-OUT term 1 then accept set firewall family inet filter RE-OUT term 2 then accept set interfaces lo0 unit 0 family inet filter output RE-OUT
For further details on preserving host outbound traffic on MX device, see Class of Service User Guide for Routers.