@Helix26404:
Hmm. Tell me if my logic is correct: if the WAN interface is shaped properly, and the traffic flows over the VPN (which goes out the WAN interface), will that traffic be shaped?
It will be shaped as part of one class. Although, since the tunnel originates from the pfSense box and our shaper setup classifies traffic as it enters the LAN interface so it can be appropriately shaped going out the WAN, what you'll likely see is the VPN traffic hitting the default class on the way out. This would apply to both the traffic outbound from your network, but also the traffic inbound to your network. At some point, I'd love to see the layer 7 changes I was working on completed so we can dynamically move traffic to appropriate queues. But until that's done, I don't expect we'll be able to shape VPN traffic of any kind properly.
–Bill