Configuring packet information pre-extraction

This feature is supported only in FIPS mode.

If you apply both an IPsec policy and QoS policy to an interface, by default, the interface first uses IPsec and then QoS to process IP packets, and QoS classifies packets by the headers of IPsec-encapsulated packets. If you want QoS to classify packets by the headers of the original IP packets, enable the packet information pre-extraction feature.

For more information about QoS policy and classification, see ACL and QoS Configuration Guide.

To configure packet information pre-extraction:

Step

Command

Remarks

1. Enter system view.

system-view

N/A

2. Enter IPsec policy view.

ipsec policy policy-name seq-number [ isakmp | manual ]

Configure either command.

3. Enable packet information pre-extraction.

qos pre-classify

Disabled by default.