A trust boundary defines where you accept QoS markings. Misplaced trust lets users manipulate their own priority.
Untrusted edge:
- User devices may send false markings
- Reclassify traffic at the access switch
- Set incoming CoS and DSCP to first
Trusted sources:
- IP phones from your vendor
- Servers you control
- Other network devices in your domain
Trust boundary placement: Usually at the access layer switch. Trust markings from the voice VLAN. Remark traffic from the data VLAN based on your classification policy.