Set and Verify DCB Application Priorities with dcb app

Add a DSCP rule twice with dcb app and it keeps both priorities instead of replacing the old one. That is exactly the kind of surprise you do not want on a live switch port. This guide covers reading a network interface's DCB application table, adding a rule, converging it onto one priority with replace, and removing it again without leaving a mess behind. The commands match iproute2 6.1.0-1ubuntu6.4, the version installed on the machine used here. Give it 10 minutes if DCB is already enabled on the interface, longer if the switch and NIC still need configuring.

Before you start

You need the dcb command from the iproute2 package, an interface whose driver supports the DCB application table, and root for anything that changes state. Every example below uses eth0 as a placeholder: swap in the real interface name before you run anything. Applying DCB settings to the wrong interface can reclassify traffic on a live link, so do not copy that placeholder unchanged.

Find the interface first. This is read-only and needs no elevated privileges:

$ ip -br link
eno1             UP             ...
lo               UNKNOWN        127.0.0.1/8 ::1/128

Set a shell variable only after you have checked the name:

$ DEV=eno1
$ dcb app show dev "$DEV"

If the interface does not support the operation, the command fails rather than inventing a table. Check the driver, kernel DCB support and link documentation before you change anything.

Checkpoint 1: record the current table

Read the complete table before touching it. The output is grouped by selector, and an empty result means there are no entries, not that the interface itself is absent:

$ sudo dcb app show dev "$DEV"
default-prio 0
dscp-prio 0:0 24:3 48:6

Your output will differ. Save it somewhere you will find again, especially on a production host. You can also ask for one selector at a time:

$ dcb app show dev "$DEV" dscp-prio
dscp-prio 0:0 24:3 48:6

The selectors are default-prio, EtherType, TCP or SCTP destination ports, UDP or DCCP destination ports, either port family, and DSCP. Priorities run 0 to 7. The DSCP key runs 0 to 63.

Add one rule and see the catch

Use add when you deliberately want to add an individual entry. This example gives priority 4 to DSCP 24:

$ sudo dcb app add dev "$DEV" dscp-prio 24:4
$ dcb app show dev "$DEV" dscp-prio
dscp-prio 0:0 24:3 24:4 48:6

Tip: seeing both 24:3 and 24:4 in the table at once is not a bug, it is exactly how the APP table model works, and it is the most common surprise in this command. add never replaces a different priority for the same selector and protocol ID, so the table can end up holding two conflicting assignments. Some output uses symbolic DSCP names from /etc/iproute2/rt_dsfield. Add -N when you want the numeric keys instead:

$ dcb -N app show dev "$DEV" dscp-prio
dscp-prio 0:0 24:3 24:4 48:6

Checkpoint 2: converge on one priority

This is the fix for the mess above. Use replace for the usual administrative change: it adds the requested entries, then strips out entries for the same selector and key that carry a different priority. Run it and DSCP 24 ends up with priority 4 only, while unrelated DSCP entries stay put:

$ sudo dcb app replace dev "$DEV" dscp-prio 24:4
$ dcb -N app show dev "$DEV" dscp-prio
dscp-prio 0:0 24:4 48:6

The replacement only touches the selector and key pairs you name. It will not clear the entire DSCP table on you. Run the read-only show command after every change anyway, so a copied command does not silently land on the wrong interface or key.

Remove a rule or restore the recorded state

To delete the exact entry created above, give the same key and priority:

$ sudo dcb app del dev "$DEV" dscp-prio 24:4
$ dcb -N app show dev "$DEV" dscp-prio

If the original table had 24:3, put it back with add, but only after checking it is actually missing:

$ sudo dcb app add dev "$DEV" dscp-prio 24:3
$ dcb -N app show dev "$DEV" dscp-prio

Warning: do not reach for flush as a shortcut to undo one change. It wipes every entry for the selected namespace, and it needs elevated privileges to do it:

$ sudo dcb app flush dev "$DEV" dscp-prio
$ dcb app show dev "$DEV" dscp-prio
(nothing)

If you did flush the namespace on purpose, rebuild it from your recorded output with one add or replace command. There is no transaction log or undo history inside dcb app, only what you wrote down.

Other selectors worth knowing

The same command shape covers other application identifiers. EtherTypes take hexadecimal values from 0x600 to 0xffff; destination ports take 1 to 65535:

$ sudo dcb app replace dev "$DEV" ethtype-prio 0x8906:5
$ sudo dcb app replace dev "$DEV" port-prio 4791:3
$ dcb app show dev "$DEV" ethtype-prio port-prio

stream-port-prio matches TCP and SCTP destination ports, dgram-port-prio matches UDP and DCCP, and port-prio covers either. Use the narrowest selector that actually matches the traffic you mean to classify. For a fallback priority, use a list with default-prio, for example default-prio 0. Under the hood that fallback is stored as an EtherType rule with protocol ID 0, but dcb app shows it under the clearer name.

Done means