• Configuring limiters immediately black holes WAN traffic?

    1
    0 Votes
    1 Posts
    377 Views
    No one has replied
  • Inbound load balancing

    4
    0 Votes
    4 Posts
    619 Views
    jimpJ

    Without a proxy there is no concept of ensuring a client gets directed to the same backend for subsequent requests, and no way to handle removing a down/unresponsive server from the pool of available targets.

  • Wireguard FQ_CODEL + ALTQ (PRIOQ)

    1
    0 Votes
    1 Posts
    508 Views
    No one has replied
  • Traffic Shaping in 23.01 - Bug?

    20
    1 Votes
    20 Posts
    3k Views
    D

    @steveits And it is fixed! Whew. Now if I can just get the box to check for updates reliably, which is yet another new issue, albeit a minor one!

  • Question - fq_codel_enqueue over limit ?

    7
    0 Votes
    7 Posts
    2k Views
    RobbieTTR

    @magikmark
    Thanks very much for the tailored advice. 👍

    The fq_codel error logs are pulled from /var/log/system.log so they also show in the GUI under Status/System Logs/System/General.

    For whatever reason the errors promptly ceased after an unrelated update & reboot, so I have not had a chance to apply and monitor the suggested values. The 'observer effect' no doubt.

    ☕️

  • Error when trying to setup traffic shaping

    3
    0 Votes
    3 Posts
    843 Views
    TheCableGuy96T

    @steveits Ahh thank you, I did Google quite a bit but didn't find that. I hope there's a solution soon.

  • I need the opposite of a Limiter? Guarenteed min BW on each VLAN

    5
    0 Votes
    5 Posts
    738 Views
    S

    @rb625 traffic shaper can do this
    https://docs.netgate.com/pfsense/en/latest/trafficshaper/altq-scheduler-types.html#hierarchical-fair-service-curve-hfsc
    I’ve not used HFSC but there are tutorials online.

    CBQ has limits and “borrowing” but I had some challenges getting it to work. IIRC one has to set borrowing on the parent queue as well.

  • Limiters only applies for in-pipe and not for out-pipe

    1
    0 Votes
    1 Posts
    287 Views
    No one has replied
  • 23.01 - Traffic shaper not working as expected

    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • Traffice Shaping / Limiters do not work on 22.05 after upgrade

    19
    3 Votes
    19 Posts
    4k Views
    A

    @level4 Thankyou, it worked

  • bufferbloat with fq_codel after update to 23.01

    22
    0 Votes
    22 Posts
    3k Views
    T

    @jeremyj-0 Unfortunately for me, setting it to CoDel didn't help at all.

    I think we and many others have different environments, so it is hard to compare. I think I need to learn how to profile both system and network first. Because before I can solve it, I have to find out if it is something with software, hardware, or maybe my ISP is breaking everything. But each part needs different tools to investigate it properly. Also, I'm making it even harder by using proxmox.

  • CoDel Pass Rule floating to the top?

    7
    0 Votes
    7 Posts
    909 Views
    M

    @nocling yep - I'm using the same rule order. I think the "Pass" option for CoDel (in the documentation) meant that it gets re-ordered to the top of the list when it should be the last thing. I've put it at the end of my list of traffic shaping "match" rules and bufferbloat tests seem consistent in behaviour to the "pass" rule at the end of all floating rules.

  • Floating Rule Action: Pass or Match

    2
    0 Votes
    2 Posts
    635 Views
    S

    @christos3105 That would be my understanding, but, if it is WAN Out that would normally always be allowed anyway (since normal rules are processed when packets enter an interface).

  • WAN & VPN Traffic Shaper: VPN speed limited to half of limiter

    1
    1 Votes
    1 Posts
    444 Views
    No one has replied
  • QoS / Traffic Shaping / Limiters / FQ_CODEL on 22.05

    59
    0 Votes
    59 Posts
    20k Views
    M

    @dennypage

    There are many ways to approach this but my suggestion does take icmp and other protocols out of the equation. The firewall floating rule ONLY includes tcp and udp. I just installed pfsense the other night and curiously ran into the same issues running ping and traceroute with my windows laptop having the “repeating” issue along with dropped pings. This change resolved my issue and still controls bloat. Cake has this feature aimed towards a 11:1 or higher rate.

    Finding a way to drop duplicate acks is another avenue worth exploring for extending the ingress bandwidth at the expense of more cpu usage. I started with openwrt and the sqm folks learning much over the years.

  • TCP ack Prioritization

    7
    0 Votes
    7 Posts
    1k Views
    M

    @mloiterman

    DiffServe Code Points? What do u mean?

    All DNS queries are given the same priority as the TCP ack. Creat a floating rule that would intercept queries on your DNS resolver provider.

    The way I set up my DNS is somethin like this:

    AdGuard Home for pfSense

    Then I use NextDNS for my upstream DNS

    What optimization have you done on your pfsense? Have you tried playing around with the System Tunables?

  • 2.6.0 can not select/see ixl0 10 GBit LAN interface

    2
    0 Votes
    2 Posts
    399 Views
    M

    @slu

    The ixl driver doesn’t support ALTQ traffic shaping.

    You can use Limiters though.

  • How to give priority to specific IP address?

    2
    0 Votes
    2 Posts
    458 Views
    S

    @enesas How are you doing it? It matters whether you have a web server or something like Teams. The web server is an incoming connection; Teams is outgoing.

    For the latter see if this helps:
    https://forum.netgate.com/post/1084271

  • Traffic by IP addresses

    1
    0 Votes
    1 Posts
    352 Views
    No one has replied
  • How to set up Limiter with slow LAN?

    4
    0 Votes
    4 Posts
    599 Views
    noplanN

    @snitem

    Limit every vlan (each for 1 appartement)
    To 60 down and 9 up

    Set the bloat limiter
    On your wan with floating rule to the exact up / down you get for your wan connection

    A fair method for all users
    They have a 60/9 connection protected by a pfS

    And you can also tweak the limiters with a time based scheduler

    But be aware limiters on 2.6 CE
    Are a bit well as far as I know not working

    BR NP

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.