# STEP_035E multiclass selector plan

No remote changes were made.

Current proven selector:

- 10.253.1.10 cs1 canary_vpn3
- cs1 currently maps to fwmark 0x203 and vpn3.

Proposed next apply, VM101 only:

- Extend VM101  to install:
  - DSCP cs1 -> fwmark 0x203 -> table 203 -> vpn3
  - DSCP cs2 -> fwmark 0x204 -> table 204 -> vpn4
  - DSCP cs3 -> fwmark 0x205 -> table 205 -> vpn5
- Keep DSCP clear-on-egress for marks 0x203, 0x204, 0x205.
- Do not change VM100 selector file yet.
- Therefore live traffic remains only canary:
  - 10.253.1.10 cs1 canary_vpn3

Proposed validation after VM101 multiclass apply:

1. Current canary traffic still works via cs1/vpn3.
2. Rules for cs2/cs3 are visible but have zero counters until selector entries are added.
3. No production-wide switch and no changes to legacy table 200.

Later, one peer at a time:

- add selector entry  only after that peer is enabled and visible on VM100 wg_paid.
- test traffic and counters.
