Hi,
An MF classifier configured as input firewall filter on the interface should be able to mark and classify selected packets on ingress:
Alternatively you could use a fixed classifier on the interface to classify all ingress packets and rewrite that forwarding class with the desired dscp marking on egress.
Cheers,
Ashvin