Start with traffic that matches the class
A QoS policy is useful only if relevant packets enter the intended class. In MQC, match-any accepts any declared criterion; match-all requires the combination of criteria. Consider a class with DSCP EF and an ACL identifying a source range. With match-any, an EF-marked packet can match even when it is outside that range. With match-all, both criteria must match. This ACL is used for classification here: do not conclude that a deny in the classifier is equivalent to blocking traffic at the interface. Also follow the remaining classes and class-default.
Case: backup traffic was marked as voice
In a fictional APS scenario, backup traffic grows inside the priority class after a server update. The application marks packets EF and the boundary accepts that marking without reclassification. Before increasing the queue reservation, compare flows, sources and classification counters before and after the change. Define which markings are accepted from each source and where they can be rewritten. DSCP expresses intended treatment; it proves neither application identity nor security authorization. An IP range authorized for classification also does not authenticate its sender. Retain the service’s access controls.
A minimum service rate is not a ceiling
In the scheduling model documented for IOS XE, bandwidth configures a minimum service guarantee for a class under supported conditions and a correctly sized policy. By itself, it is not a policer discarding every bit above that value. A class can use additional available capacity according to the scheduler. If the operational reference for bandwidth percent is 100 Mb/s, a 30% reservation represents 30 Mb/s; do not automatically use a physical speed of 1 Gb/s when the context reports a different reference. bandwidth remaining percent concerns distribution of remaining capacity and should not be read as an equivalent percentage of total capacity.
Priority and excess control
A priority queue can reduce waiting for the selected class but does not eliminate serialization, downstream congestion or configured limits. Confirm whether the platform and policy use congestion-conditional policing, always-on policing or another supported mechanism. Documentation distinguishes these options; do not generalize one command’s behavior to all hardware. Priority without adequate control can compromise other classes. In the project, define admitted load, excess behavior and delay requirements, including degraded operation. If sustained demand exceeds available service, priority configuration only determines where impact appears.
Accept policy through observed outcomes
The excerpt below is for interpretation and was not executed on IOS XE. ORIGENS-VOZ selects a fictional range and BATCH identifies AF21; names do not guarantee actual flow content. For implementation, confirm platform support, the interface and direction where service-policy is attached, classes receiving traffic, reference rates, drops, queue occupancy and application behavior. Also observe traffic that should not enter priority. Retain counter deltas over a known interval; a cumulative total without timing context may belong to earlier traffic. The next lesson’s simulator verifies logic and arithmetic, not these counters on a device.
! Reading exercise only; not executed on IOS XE.! Confirm platform support, rate reference and attachment before deployment.
ip access-list extended ORIGENS-VOZ
permit ip 192.0.2.0 0.0.0.255 any
class-map match-all VOZ-AUTORIZADA
match dscp ef
match access-group name ORIGENS-VOZ
class-map match-any BATCH
match dscp af21
policy-map WAN-LEITURA
class VOZ-AUTORIZADA
priority percent 10
class BATCH
bandwidth percent 30! No service-policy attachment is included in this reading excerpt.
EF true and source outside the range: match-any accepts; match-all rejects this combination.
Common pitfalls
DSCP as identity; classifier ACL as firewall; bandwidth as a ceiling; percentages without operational reference.
Related topics: QoS: bursts, queues and delay budgets · Architecture and surviving capacity
Check who enters the class, what treatment it receives and where policy is attached.
Reference: QoS Scheduling · 350-401 ENCOR v1.2, effective 2026-03-19; core component of CCNP Enterprise