Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic Shaping and IPSEC

    Scheduled Pinned Locked Moved Traffic Shaping
    6 Posts 5 Posters 5.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      joyfulway
      last edited by

      Hi,

      Is traffic shaping on IPSEC supported on the last pfsense version 1.2.3-RC3 ?

      I'm using IPSEC to connect a remote site to a main location and would like to shape the traffic in this pipe.
      Both sites are connected with a pfsense router on the OPT1 Interface.

      Thanks,
      cocacolle

      1 Reply Last reply Reply Quote 0
      • D
        dcalvache
        last edited by

        Hi Guys..

        Is this working? on any version of Pf sense?
        I really need this? any suggestion with this software or another?

        1 Reply Last reply Reply Quote 0
        • A
          althornin
          last edited by

          Currently in 1.2.3 this does not work.
          You can shape things so that IPSEC has higher/lower priority, but to shape the actual contents of the IPSEC tunnel, you'd really need a setup like this:

          PFSENSE<–>PFSENSE<--IPSEC-TUNNEL-->PFSENSE<-->PFSENSE

          Where the outer two pfsense boxes would shape the traffic, and the inner two contain the tunnel.  Kinda a pain.

          1 Reply Last reply Reply Quote 0
          • E
            eri--
            last edited by

            Actually on 1.2.3 you can shape inside the tunnel but i am not sure if the rules allow this to be setuped.
            On 2.0 it is surely possible.

            1 Reply Last reply Reply Quote 0
            • J
              joyfulway
              last edited by

              Hi ermal,

              do you mean I have to manually write the rules to shape the traffic ?

              1 Reply Last reply Reply Quote 0
              • L
                lagreca
                last edited by

                @ermal:

                Actually on 1.2.3 you can shape inside the tunnel but i am not sure if the rules allow this to be setuped.
                On 2.0 it is surely possible.

                In 1.2.3 how do you shape inside the tunnel?  Would it be with firewall rules?  Or a traffic shaper rule?

                I'm curious because we have remote SIP extensions I would LOVE to run over our IPSEC instead of the internet.  But they also run a lot of SMB traffic over IPSEC, so I absolutely HAVE to shape the data within the tunnel for it to sound good.  Thanks.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.