My XG 330 HA pair is at our co-lo and protects multiple locations connected on the LAN port via private WAN links.
There is one WAN link providing internet access to all locations.
We have two IPSec tunnels to two different hosted applications.
I want to ensure that traffic coming in from these two tunnels to the LAN receives DSCP markings so that my private WAN providers core and edge routers will prioritize the traffic.
The following rule is being processed when viewing the logs, but WireShark shows the tagging is not being applied.
I called support and escalated the case, but am still waiting for a reply from their recent packet capture.
What config have I missed, or how should I adjust this rule to properly mark the traffic?
Thanks.
This thread was automatically locked due to age.