508 Configuring and managing security ACLs
NN47250-500 (Version 03.01)
The following commands perform the same CoS reassignment as the commands in “Using the dscp option” on page 507.
They remap IP packets from IP address 10.10.50.2 that have DSCP value 46 (equivalent to precedence value 5 and ToS
value 12), to have CoS value 7 when they are forwarded to any 10.10.90.x address on Distributed AP 4:
WSS# set security acl ip acl2 permit cos 7 ip 10.10.50.2 0.0.0.0 10.10.90.0 0.0.0.255 precedence
5 tos 12
success: change accepted.
WSS# set security acl ip acl2 permit cos 7 ip 10.10.50.2 0.0.0.0 10.10.90.0 0.0.0.255 precedence
5 tos 13
success: change accepted.
WSS# set security acl ip acl2 permit any
success: change accepted.
WSS# commit security acl acl2
success: change accepted.
WSS# set security acl map acl2 ap 4 out
success: change accepted.
The ACL contains two ACEs. The first ACE matches on precedence 5 and ToS 12. The second ACE matches on prece-
dence 5 and ToS 13. The IP precedence and ToS fields use 7 bits, while the DSCP field uses only 6 bits. Following the
DSCP field is a 2-bit ECN field that can be set by other devices based on network congestion. The second ACE is
required to ensure that the ACL matches regardless of the value of the seventh bit.

Enabling prioritization for legacy voice over IP

WSS Software supports Wi-Fi Multimedia (WMM). WMM support is enabled by default and is automatically used for
priority traffic between WMM-capable devices.
WSS Software also can provide prioritization for non-WMM VoIP devices. However, to provide priority service to
non-WMM VoIP traffic, you must configure static CoS or configure an ACL to set the CoS for the traffic. The AP maps
the CoS value assigned by static CoS or the ACL to a forwarding queue. The examples in this section show how to
configure CoS using ACLs. To use static CoS instead, see “Configuring static CoS” on page 435.
Note. You cannot use the dscp option along with the precedence and tos options in the
same ACE. The CLI rejects an ACE that has this combination of options.