QoS Bandwidth Allocator
Allocate link bandwidth across traffic classes with the right DSCP markings and queueing behaviour, and generate the policy map, checking the constraints that make a QoS design work.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
QoS only matters when the link is full
On an uncongested link every packet is forwarded immediately and no queueing policy changes anything. QoS is entirely about what happens during the seconds when more traffic arrives than the link can carry, deciding which packets wait and which are dropped. This is why measuring the effect of a QoS change is difficult: it makes no difference at all until the moment it makes all the difference, and that moment is usually brief.
Priority queues need a policer
Voice traffic goes in a strict priority queue, which is serviced before everything else. Without a bandwidth limit on that queue, any traffic marked as voice starves every other class completely, and a misconfigured application or a marking that survives from an untrusted network becomes a denial of service. Every priority queue therefore needs a policer, and the total across all priority classes should stay around a third of the link.
Markings from outside cannot be trusted
DSCP values are set by the sending host and any application can set them. A device that trusts incoming markings gives every user the ability to place their traffic in the priority queue by changing one setting. The standard practice is to clear or remark DSCP at the network edge and only trust markings from devices under your control, such as IP phones identified by their voice VLAN.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
What DSCP values should I use?
EF (46) for voice, CS3 (24) for call signalling, AF41 (34) for interactive video, AF31 (26) for streaming, AF21 (18) for transactional data, CS1 (8) for scavenger traffic and default (0) for everything else. These are the standard values from RFC 4594 and most equipment defaults align with them.
Why does a priority queue need a limit?
Because it is serviced before every other queue, so without a limit any traffic marked into it starves everything else completely. A misconfigured application or a marking from an untrusted network then becomes a denial of service against the whole link.
How much of the link can voice have?
Around a third at most, across all priority classes combined. Beyond that, other traffic is starved during call peaks and the link becomes unusable for everything else, while still not guaranteeing voice quality under genuine congestion.
Should I trust incoming DSCP markings?
Only from devices you control. Any host can set any DSCP value, so trusting markings from user devices lets anyone place their traffic in the priority queue. Clear or remark at the edge and trust only identified devices such as IP phones on a voice VLAN.
Does QoS help on an uncongested link?
No. Every packet is forwarded immediately when there is capacity, so no queueing policy changes anything. QoS decides what waits and what is dropped during congestion, which is exactly why its effect is hard to measure until the moment it matters.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Set your link speed and allocate a percentage to each traffic class to generate a QoS policy.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.