> Source: [sk145132](https://support.checkpoint.com/results/sk/sk145132)

# sk145132 - DSCP value in IP header is changed on a Security Gateway with QoS disabled

| Property | Value |
|----------|-------|
| Solution ID | sk145132 |
| Date Created | 2019-02-05 |
| Last Modified | 2022-04-06 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- The DSCP value in an IP header is changed on a Security Gateway with QoS disabled.

## Cause

The connection is transparently proxied when the Check Point Active Streaming (CPAS) is in effect.

* One connection is between the client and the Security Gateway.
* The other connection is between the Security Gateway and the destination.

In order to use the same DSCP value even though the connection is transparently proxied, the value would have to be copied from the packets from one side to the other.

However, as the SYN-ACK from the Security Gateway to the client is generated and sent before the SYN-ACK is received from the destination, the DSCP value cannot be copied.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
