• Squid + lusca + squidguard + trafic shaper

    2
    0 Votes
    2 Posts
    3k Views
    D

    Squid have self traffic settings.
    Use Traffic shaper for different protocols, then http (not squid traffic).

  • Priority via multiple Interfaces including VLANs

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • PF Sense 2.0.3 multy WAN Traffic Shaper error

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Wizard - VOIP - Connection #1 parameters ??

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Limiter not going above 1meg down.

    7
    0 Votes
    7 Posts
    3k Views
    J

    All PC's are given access to internet individually through firewall. Some PC's only need access for antivirus updates, checking mail, light browsing. Then, other PC's interact with customer services and online research, in addition to checking mail, antivirus updates. Last set of PC's do torrents.

    So, I need to set 3 types of limiters, for light, medium, and large users, then assign those limiters to individual rules on the firewall. Yes, IP addresses are fixed.

  • Need help : ask about WAN bandwidth

    3
    0 Votes
    3 Posts
    1k Views
    F

    @pratchaya:

    My ADSL router hv 12000/1200 kbps speed .
    ( 12M/1M )

    Looks normal but enter; for 12000/1200 kbps speed
    1024 Uoload
    12288 Download

  • QOS for voip

    2
    0 Votes
    2 Posts
    1k Views
    R

    I would like one also. Just purchased an ooma on sale from newegg and would like to use it on my lan running from my pfsense box :)

  • Shaping upload bandwidth with hfsc

    2
    0 Votes
    2 Posts
    3k Views
    D

    I partially solved my problem. So I answer my own question  :D

    I was messing with traffic shaper wizard, I found out that, if I create same queue name on both WAN and LAN, lets say qP2P, and if I set a floating rule for P2P traffic and set its queue name qP2P ( without ackqueue, its important). Download traffic goes to LAN's qP2P and upload traffic goes to WAN's qP2P, ack packets also goes to these queues. So I solved my own problem.

    But I couldn't solve my latency problem entirely,
    If I fully saturate upload (WAN traffic) my latencies dont get affected that much. I have read that WAN traffic is the one that we can control, the traffic that we can actually control by prioritizing packets or dropping, it is the the traffic that we create. On the other hand, download traffic is the one that we cannot control directly, someone could send us packets and we cannot stop it until it reaches our pfsense router.
    So my problem starts here, when i fully saturate my download traffic, latencies start to go high, not high as 600ms or 900ms but 200-250 ms.
    I'm testing latencies with ping command, i gave it highest priority, i tested different schedulers, for both LAN and WAN, I couldn't solve this problem.
    Traffic shaper solves my bandwith problem, I can enjoy smooth web browsing, every queue can get its fair share of bandwith, but latencies are too high for gaming when download queues are saturated

    So experienced users can give me an advice, is it normal to have high latencies like mine, can it be solved?

    Thank you in advance

  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • Basic WAN limiter

    3
    0 Votes
    3 Posts
    2k Views
    G

    Thanks, but I really need to limit at the interface level (Entire WAN)

  • Limiting traffic video for pfsense

    3
    0 Votes
    3 Posts
    3k Views
    F

    youtubes uses FLV and MP4.

  • Limiting bandwidth between certain hours, which way is the best?

    7
    0 Votes
    7 Posts
    4k Views
    P

    Also if possible, id like to limit the bandwidth usage to 300GB per month.  Then close to 300GB, I'd get a notification from pfsense and at 300GB pfsense would close all connections until the billing cycle restarts..

    This is also a fu7ndamental feature I'd like to implement.  At $1.50 per GB, its not long before the bills go up.

    Can pfsense limit the amount of data per time cycle (per month, per day, etc….)???

  • WAN limiting?

    2
    0 Votes
    2 Posts
    2k Views
    S

    All you should need to do is run the traffic shaping wizard and plug in your numbers (10/10) and it will be limited.  That will get you the basics.  Beyond that you can fine tune the traffic shaping by:

    Using floating rules and establishing alias's for gaming ports and then putting in rules and queues to limit traffic. So basically you would have

    WAN - HFSC 9MB (this is your upload)

    qNerf - Default - 5% qWebSteam - 15%
    -qAck -30% qGaming - 50%

    LAN - HFSC
    -qInternet - 10MB (this is your download)
    –qAck - 20%
    --qNerf - Default -5%
    --qWebSteam - 10%
    --qGaming - 65%

    qACK will be for TCP ACK packets
    qWebSteam will be for 80,53 , and steam ports for upload / download , etc
    qNerf will be for any traffic not recognized
    qGaming should be for all your gaming traffic

    This will require you to know the ports for the games people are playing and either make rules for each port set per game or make an alias called gaming ports , put all the ports in it and use that in your floating firewall rule.

    Sometimes games can be tricky about what ports are being used so the best way to figure this out is to put up PFSense , run a PC behind it  and have it play the game and run a port capture on it to see what ports the game is actually using.  You can export the capture from PFSense to Wireshark.  This will be the part that will be the hardest to do , getting the games qualified into proper port mappings and then having them hit the correct queues.

    Running a 10/10 Internet connection with anything over 50 people is going to be rough as games like LoL (League of Legends) and others will tax it if your doing a tourney.  For 250 people I would see if you could get another 10MB on download and give up 5MB on upload.  If you see someone uploading alot ,then typically they are running a file sharing app and you need to shut them down.  I would recommend using PRTG as well and make a port mirror on your switch so you can see the traffic and monitor it and when you see someone hogging the bandwidth - I do the following:

    1. See what traffic / port they are passing and to what IP if it resolves.
    2. Find the MAC of the PC . Make a static reservation in PFSense for that MAC to get a static IP.
    3. Delete their current lease to force them to renew and get your static IP.
    4. I make a LAN rule to block all traffic for that MAC to any connection on the network.
    5. Now you can wait for someone to come up and say they can't get to anything and you can see what they were doing.
    Typically they will have something like Spotify running or some other file sharing application.

    If you have better switches and you can see what table switch port they are on , then you can just shutdown the port  but alot of LAN's just run dumb gigabit switches at the tables and a Layer2 at the core for the most part. The above way is effective in shutting them down.

    I would recommend thoroughly testing out your configuration by doing the above with a couple of PC's so you can see how it is going to perform.  You will need to use Intel NIC's in the PFSense box for the best performance.

    Btw - I run the network / Internet for LAN's that are about 120 people in size and we usually have 2 or 3 50/5 cable modems for our Internet and use load balancing with a similar config. I run a PRTG box to monitor my stats and I run a Dell Poweredge 2950 server with ESXi 5 that holds all our gaming servers. We use an Intel Dual Core 3GHZ 8G RAM , 80G SATA , 4 Intel Gigabit NIC PC running PFSense.

    Sorry for the long post but the best advice I can give you is test , test , test before the event.

  • Traffic Shaper and port number tracking clarification please.

    3
    0 Votes
    3 Posts
    1k Views
    J

    Ok. Thanks for the clarification. I understand now.

    Jits.

  • Would pfsense work for me to shape traffic this way?

    2
    0 Votes
    2 Posts
    1k Views
    C

    The easy way to do it is with limiters, not running through the full blown shaper. Create the up and down limiters as desired for the hosts to be rate limited, configure as needed in firewall rules.
    http://doc.pfsense.org/index.php/Traffic_Shaping_Guide#Limiter

  • Traffic Shaper not queing properly

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Limiters not working as expected…

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Custom Traffic Shaper rules in 2.0.x

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    T

    Another functionality is logging firewall rules to external MySQL database
    I would like to add this via option in Shaper Wizard with option fields like:
    database server
    database name
    database user
    database pass
    as far I know this can be done with Remote syslog server like this:
    http://doc.pfsense.org/index.php/Copying_Logs_to_a_Remote_Host_with_Syslog
    This would be configured on syslog-ng host - question is: is it compatible with pfSense syslog?
    http://www.gho.no/2008/10/setting-up-remote-syslog-to-mysql-with-cisco-ios-and-syslog-ng-in-linux/

    I'm currently running on 2.0.3 i386.

  • Proper use of Layer7 to "block" bittorrent, p2p, etc.

    Locked
    2
    0 Votes
    2 Posts
    8k Views
    cmcdonaldC

    I am also confused with something as well. pfSense firewall rule theory is still a bit new to me and requires me to really think about rules before creating them. I know that rules are executed when packets are received on the rules respective interfaces. I believe that floating rules are executed when "any" packets are received from "any" interfaces? Also, once a rule matches a packet, do other rules get executed as well? For example, lets say I wanted to create a few different layer 7 containers and apply numerous filters to an interface? Are the containers involved in determining whether or not a packet matches a rule? That is what's confusing me.

  • How to easily identified queues in RRD graph?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S

    I don't think you can do that from the webinterface, sorry. Found the color thing though, does that help:
    http://forum.pfsense.org/index.php?topic=16463.0

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.