To configure a filter sequence to match packets based on DSCP or IP Precendence values, use the set firewall filter sequence from ip value command in L2/L3 configuration mode.
set firewall filter filter-name sequence number from ip value value
delete firewall filter filter-name sequence number from ip
|number||Filter sequence number. The range is 0-9999.|
DSCP or IP Precendence value, according to the trust mode configured with the set firewall filter sequence from ip trust-mode command. The range is 0-7 for IP Precedence, and 0-63 for DSCP.
The following example configures the trust mode for sequence 2 of MyFilter filter to DSCP. The DSCP value used to match packets is then set to 2.
The following example removes the trust mode and DSCP value from sequence 2 of MyFilter filter: