> Source: [sk32176](https://support.checkpoint.com/results/sk/sk32176)

# sk32176 -  Quality of Service (QoS) Limitations

| Property | Value |
|----------|-------|
| Solution ID | sk32176 |
| Date Created | 2006-11-27 |
| Last Modified | 2026-05-04 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

Show the Entire Article

<br />

### Enforcing Differentiated ServiDiffServ on Marked Packets

Show / Hide this section  
Network nodes that support Differentiated Services typically perform the following operations:

* Classify incoming packets based on IP address or service information and mark the Type of Service (TOS) field in the IP header with a Differentiated Services Code Point (DSCP) value.  

* Apply a QoS policy to incoming packets based on IP address or service information.  

* Apply a QoS policy - specifically, Per-Hop Behavior (PHB) - to incoming packets based on their existing DSCP values.

Check Point QoS only performs the first two operations; it does not evaluate the existing DSCP value of incoming packets. Therefore, to integrate Check Point QoS into a DiffServ environment, reclassification and re-marking of packets are required, necessitating redefinition of classification rules.
****Considerations:****

* A non-QoS Gateway does not modify DSCP bits.
* A QoS Gateway can modify DSCP bits if configured accordingly.
* If a QoS Gateway functions as a proxy, DSCP tags are not retained in outgoing packets.

**Example** :   
If a Check Point QoS Gateway is positioned behind a DiffServ-enabled router, VoIP traffic (class EF) must be configured on both the router and the Check Point QoS Gateway.   

This issue arises only when a Check Point QoS Gateway is behind a router. If the Gateway is at the border of the DiffServ-enabled network, it marks the packets.

### Support for Peer-to-Peer (P2P) and Instant Messaging

Show / Hide this section  
Check Point QoS does not support file transfer and instant messaging traffic over HTTP (port 80 tunneling). Consequently, lowering bandwidth for file transfers over HTTP is not possible without affecting regular HTTP browsing traffic.
**Note:** It is possible to control P2P traffic if it uses a different, known port. For controlling such traffic. it is possible to use the P2P_File_Sharing_Applications service.

### Support for ClusterXL when the physical IP addresses of cluster members and the Cluster Virtual IP address are configured on different subnets

Show / Hide this section  
QoS recognizes the cluster members according to the network subnet of the cluster.

If the physical IP addresses of cluster members and Cluster Virtual IP address are configured on different subnets (which is a supported configuration), QoS does not recognize the cluster members. In such a configuration, QoS rules might not be applied. Refer to [sk105610](http://supportcontent.checkpoint.com/solutions?id=sk105610) for more information.

### IPv6 Limitations

Show / Hide this section  
*
  * SmartView Monitor does not display QoS-related information.
  * DSCP marking is not supported.
  * IPv4 and IPv6 QoS trees operate independently, leading to incorrect bandwidth calculations when both are used simultaneously.

### Authentication Limitations

Show / Hide this section  
*
  * QoS rules configured with authentication are not enforced.

### Domain Name Limitations

Show / Hide this section  
*
  * QoS rules configured with domain names are not enforced.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
