• 7 people in this house - solve with limiters?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Queues understanding effect

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: 'pfctl: jme0_vlan10: driver does not support altq'

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to block torrent traffic on pfSense ?

    Locked
    10
    0 Votes
    10 Posts
    55k Views
    E
    The snort tagging would be only useful if snort is put inline. Furthermore the encryption of torrent will just make it impossible for snort as well to detect it.
  • QoS lowest priority

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0 Votes
    8 Posts
    10k Views
    D
    Ideally you should use the traffic shaper, to ensure that business traffic gets priority over bulk downloads, instead of using a hard bandwidth cap via the CP limiters. It's also a decision between favoring best utilization of bandwidth vs consistency. Anyway, the biggest problem with P2P traffic is that it's quite difficult to identify (in order proceed to the next step of limiting it).
  • Traffic shaping on bridge lan wan (queues for protocols)

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 5 people in this house

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    marcellocM
    If CAP is captive portal you do not need subnets, just include your Mac on bypass list.
  • Nice video tutorial on simple usage of limiter

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    C
    I should mention that I didn't create the video, that was somebody on DSLReports, but he did such a good job of it I had to share it here.
  • ADSL+2 Dlink500B II modem using bridge +PFsense sytem questions!!!!

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Limit all workstations to max download\upload rate, per machine

    Locked
    6
    0 Votes
    6 Posts
    9k Views
    F
    @clarknova: When you create a shaper rule on the floating interface without the quick option, the rule will apply to any matched packet and the packet will continue to be compared to your firewall rules for a match. Rules on the non-floating interface are implicitly quick, so if your packet matches a floating rule and some other firewall rule, both rules will normally apply. Thanks for your advice here. I keep trying to make the floating interface rules work, but it's just not showing up for me. I create limited with no mask so they will apply to all traffic rather than create one queue per address, then I create a floating rule with pass or queue policy (doesn't seem to matter), setting an interface (WAN or one of the LANs), a direction, and selecting limiters in in/out in the advanced section. I reset the states to wipe out any existing connections, and look in the limiter info page. I don't see buckets getting filled in as I do for the rules on a fixed interface with a source or dest mask in the limiter. Any ideas what I'm doing wrong? Thanks,     - Tim.
  • Battlefield 3 Floating Rules Order

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    a-a-ronA
    @KurianOfBorg: I found it too much of hassle to define outbound rules for games. Only inbound ports are properly documented. You might as well make a pass-all exception for your IP address/MAC address since if you're playing games on the workstation, it's already been "compromised" with stuff running with administrative access. You really only need to have one port opened by Origin to allow full connectivity for BF3. You shouldn't need to physically open all the ports they require. The ports I have listed above do seem to work for outgoing. I have allowed 3 additional port ranges for "incoming" now so all BF3 QoS traffic is prioritized (to my best guess). Remember this is QoS, not actually physically opening ports. EA uPnp Port: 3659 keep state udp xxx.xx.x.xx EA Tunnel Additional Incoming Ports: UDP * 25200 - 25300 * * * qGames TCP * 42127 * * * qACK/qGames TCP * 9988 * * * qACK/qGames
  • MOVED: IP/Port Redirect

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Dynamic Shaping per IP

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    Run the traffic shaping wizard. About the third or forth page in you will have the option to set different protocols to different priorities - high, normal, and low. Change NNTP to low.
  • Traffic shapping Wizard error Single Lan Multi Wan

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R
    bump
  • {possible BUG] ECN is disabled, so altq can't use it?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    L
    well, ever since I enabled the flag, ECN tests work.  Without this set, even with ECN enabled in traffic shaper, ECN tests fail.  Perhaps it should be force set if enabled in traffic shaper.
  • Howto applying zph patch on LUSCA r14850

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    D
    Remember that only the traffic that comes from squid's cache will be marked. So you have to keep an eye at squid's log (tail -f /var/log/squid/access.log) to see if cache HIT are sent with appropriate tos (using tcpdump). It worked as expected when I tested it a few months ago.
  • How do I detect bandwidth hogs?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Ipfw-classifyd skype block not work

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    N
    @ermal: The skype pattern is not correct and needs to be fixed. I noted this quite late so you have to edit or create a custom pattern for it to work. Hi ermal, I do not use skype in layer 7. So is there another pattern which is not correct or is it another problem ? Is there any other way to find out which pattern makes the problem instead of just select and unselect one ? Thanks
  • PRIQ not working as expected

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.