trying to mark/identify ssh and sftp traffic

Looking to identify ssh by its ToS or dscp field if possible.

It might be me, but it seems the tools in the router are not setup to identify this?

v3.20 x86..

Help is appreciated.

you can’t identify ssh or sftp by dscp (ex tos) if somebody or somethins is not marked it for you before.
You can identify ssh/sftp traffic by destination port (22) and protocol (tcp) or by special L7 filter pattern.