Classification and Marking 157
when the switch connects to a Cisco IP Phone. These switches achieve this level of security
by using the CDP. Because all Cisco IP Phones send CDP periodically and on linkup by
default, the switch learns of connected Cisco IP Phones dynamically. When using this
configuration option with trusting enabled, these switches only trust ingress frames when a
Cisco IP Phone is attached. If the switch does not detect CDP packets from a Cisco IP
Phone using this configuration, the switches use the port CoS configuration for determining
CoS values associated with ingress frames. Because CDP is a proprietary protocol, only
Cisco IP Phones support CDP.
To configure a switch interface to trust CoS only when a Cisco IP Phone is attached, use the
following interface commands:
mm
mm
ll
ll
ss
ss
qq
qq
oo
oo
ss
ss
tt
tt
rr
rr
uu
uu
ss
ss
tt
tt
cc
cc
oo
oo
ss
ss
mm
mm
ll
ll
ss
ss
qq
qq
oo
oo
ss
ss
t
t
tt
rr
rr
uu
uu
ss
ss
tt
tt
dd
dd
ee
ee
vv
vv
ii
ii
cc
cc
ee
ee
cc
cc
ii
ii
ss
ss
cc
cc
oo
oo
--
--
pp
pp
hh
hh
oo
oo
nn
nn
ee
ee
To configure a switch interface to trust DSCP only when a Cisco IP Phone is attached, use
the following interface commands:
mm
mm
ll
ll
ss
ss
qq
qq
oo
oo
ss
ss
tt
tt
rr
rr
uu
uu
ss
ss
tt
tt
dd
dd
ss
ss
cc
cc
pp
pp
mm
mm
ll
ll
ss
ss
qq
qq
oo
oo
ss
ss
tt
tt
rr
rr
uu
uu
ss
ss
tt
tt
dd
dd
ee
ee
vv
vv
ii
ii
cc
cc
ee
ee
cc
cc
ii
ii
ss
ss
cc
cc
oo
oo
--
--
pp
pp
hh
hh
oo
oo
nn
nn
ee
ee
Example 6-10 illustrates a sample configuration of an interface on a Catalyst 3550
configured for trusting DSCP when a Cisco IP Phone is connected to interface FastEthernet 0/1.
Classifying Traffic by Using ACLs
The Catalyst 2950 Family and 3550 Family of switches support standard and extended IP
ACLs and MAC ACLs for security and QoS purposes. For QoS purposes, these switches
utilize ACLs in class maps for classifying packets. Using ACLs for classification allow for
granularity when classifying packets. By using ACLs for classification, for example, the
switch can classify packets that match only specific IP addresses or Layer 4 ports.
These switches use class maps to organize and group multiple ACLs for application to policy
maps. Policy maps group class maps and class actions such as trusting, marking, and policing.
Example 6-10 Sample Interface Configuration of Classifying Frames Based on DSCP and Whether an IP Phone Is
Connected to an Interface
Switch# show running-config
Current configuration : 157 bytes
!
(text deleted)
interface FastEthernet0/1
switchport access vlan 53
switchport voice vlan 700
no ip address
mls qos trust device cisco-phone
mls qos trust dscp
spanning-tree portfast
(text deleted)
end