• Limit single hosts bandwidth through IPSEC tunnel 2.1.4

    5
    0 Votes
    5 Posts
    2k Views
    KOMK
    Usually you open it up to allow initial synchronization, and then throttle it back for incrementals.  He needs to determine the size of the dataset he's sending per day and then break it down to see how much bandwidth he has to play with, how much he can dedicate to the backup job, and how long it will take at that rate.  Then he can craft a limiter that gives it just enough bandwidth to complete the daily job in the allotted time.
  • Firewall rules, Traffic shaping, LAN vs WAN & In vs Out

    19
    0 Votes
    19 Posts
    8k Views
    G
    @vindenesen: @georgeman: … shaping multi-LAN does not work as you expect. For reasons and an explanation on how the shaper works, check this post I have just written. Regards! Sorry if this is considered hijacking a thread, but just one small question: Does this apply to all shaping disciplines? I'm considering using the PRIQ shaper in a LAN party (which will have multiple subnets/VLANs) to prioritize gaming and other important traffic to/from the Internet. The Internet connection speed will be 1Gbps, if that makes any difference. Yes, it is the same for any scheduler since this is originated from the fact that you cannot have the same queue applying to multiple interfaces simoultaneously. Since download is "shaped" (and I put it in between quotes because you cannot really shape download, but do some TCP based tricks) on the LAN side, you are actually having multiple download pipes not communicating with each other
  • WAN AckQueue on VOIP Shaping

    16
    0 Votes
    16 Posts
    4k Views
    B
    @klou: Thanks for all of your help. klou, did you get this working correctly?  Just wondering . . .
  • 0 Votes
    9 Posts
    5k Views
    R
    Fun he says.. LOL.  Nah I read you, this QoS/Shaping stuff is damn confusing enough without the GUI lying to me hehe.
  • Traffic shaper and gaming

    20
    0 Votes
    20 Posts
    6k Views
    KOMK
    I don't think there is anything you can do about it. If you haven't noticed any in-game issues or network gameplay features not working then I really wouldn't be concerned.  It may be as simple as a heartbeat check for game clients that are no longer there.
  • Tweaking queues..

    4
    0 Votes
    4 Posts
    1k Views
    KOMK
    I haven't played with L7 rules as it seems extremely complicated, and you have to know packet byte-patterns etc.
  • Problem: when i active limiter on lan, I have high latency on gateway!!

    6
    0 Votes
    6 Posts
    3k Views
    C
    little update: i have rebooted my pfsense and now all is ok. Ok ping, ok limiter. But i have another problem, i hope that is a little problem. in my case i have: wan - pfsense guest03 - lan1                                   - lan2                                   - lan3 If i try to ping from lan1 to lan2, it run. But this is not right, because each lan is for one customer. I try with this step: i created aliases with: Type: network(s) and 192.168.0.0 CIDR 16, in this mode i have all local lan in an alias. i created 3 rule for each lan, in this mode:                 a) pass from LAN net to LAN net – no limiters                 b) block from alias to alias -- no limiters                 c) pass from LAN net to any --- with limiters Now, i have a good ping, i have my limiters and i cannot ping other lans from my lan. But i want ask: can i do this with Interface Groups? I thins that this is more simple and fast. One rule for all interfaces! Tnx for your reply
  • Need help "discouraging" game play

    4
    0 Votes
    4 Posts
    1k Views
    KOMK
    Floating rules are used in conjunction with a traffic shaper to allow you to apply rules regardless of interface (the rule "floats" above the interfaces, so to speak.)  Typically, you use it to shunt traffic in to a particular queue but you can also use it to shunt that same traffic into a limiter.
  • PRIQ or HFSC

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    S
    Trying to use HFSC with bittorrent and streaming media can be frustrating. They are hard to shape due to many reasons that you can find on this forum. Go with PRIQ , set priorities and then use a limiter as well to help restrict what you want to restrict. You can try my HFSC setups I have on the forums but again they are not optimized for restricting bittorrent and streaming media.  They are geared for LAN party configurations where allowing max bandwidth for gaming is the overall goal.
  • Limit a 1 IP on Lan not the Rest.

    3
    0 Votes
    3 Posts
    980 Views
    D
    I have the rule setup on the lan side.  With a single host which is his ip and at the bottom theres a choice for a limiter and i added the inbound and outbound limiter. At the top of the list. When i get a chance today ill take some screen shots.
  • L7 limit doesn't work for bittorent

    2
    0 Votes
    2 Posts
    856 Views
    KOMK
    Limiters are assigned using firewall rules via the In/Out section under Advanced features.  Bittorrent can be very hard to trace because the torrent clients these days use encryption and that can't be handled by a layer7 rule.  You might be better off using an opposite approach where you elevate known traffic like web and mail, and all others can be limited or shaped.
  • After traffic shaping in place, pfSense has slow updates

    1
    0 Votes
    1 Posts
    642 Views
    No one has replied
  • Layer 7

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • P2P traffic shaping in Limit?

    5
    0 Votes
    5 Posts
    1k Views
    I
    The old pfsense shapper was one idea easy for configuration.
  • Traffic Shaping Help

    2
    0 Votes
    2 Posts
    863 Views
    KOMK
    From what I understand, a limiter is just a dumb pipe that will limit all traffic routed to it to its maximum capacity, and not per client/server.  IN on the WAN interface means traffic coming from the Internet, OUT means traffic destined to the Internet.  Set your OUT to 10MB/s, set rules to move your server WAN traffic to the limiter, put them under load and see it it holds steady at ~10MB.
  • Limit bandwidth of specific port

    8
    0 Votes
    8 Posts
    4k Views
    KOMK
    Don't be concerned about packet drops.  When you have an active shaper in place, drops are expected when the router is under load.  You want packets from your lower-priority queues to get dumped in favour of packets from higher queues when there is contention or service guarantees to maintain.  That's how the whole thing works.  If you don't have any drops, you likely don't even need traffic shaping at all.
  • Limit rule based on all traffic or per client connection?

    2
    0 Votes
    2 Posts
    860 Views
    G
    per second
  • Slow WAN, Multi LAN Traffic Shaping

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Limit on Server IP not working?

    4
    0 Votes
    4 Posts
    1k Views
    W
    I want to Limit all my servers behind the DMZ . So i have server A server B and server C . what is the best Way to limit the inbound and outbound traffic to a max of 50MB per server.
  • Squid custom acl

    2
    0 Votes
    2 Posts
    1k Views
    KOMK
    First step would be to post this in the Packages forum where it belongs. Start here: https://doc.pfsense.org/index.php/Setup_Squid_as_a_Transparent_Proxy Come back if you have questions or problems.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.