Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic Shaping over the Tun0 Open VPN Interface?

    Scheduled Pinned Locked Moved Traffic Shaping
    4 Posts 2 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jeffbearer
      last edited by

      I did a search and found this bit on how you can't shape over the vpn interface. It's old and perhaps not the best informed answers.

      http://forum.pfsense.org/index.php/topic,3013.msg18132.html#msg18132

      Please review my thoughts and let me know if and where I go wrong.

      I get it that you can't shape the vpn traffic on the wan interface because it's already encrypted and it all looks like the same ssl traffic.  But can't you shape traffic going out the tun0 interface?  wouldn't you see that before it's encrypted and sent out the wan interface?

      Also What are the thoughts of assigning tun0 to an OPT interface in the gui so you can use it as an interface for traffic shaping?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        You can assign a tun0 as an opt if you want (check the doc wiki in my sig, it's under openvpn filtering)

        I haven't tried shaping, it might work.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          jeffbearer
          last edited by

          Thanks for the info,  only question I have about your wiki, what is the syntax to specify the tun device name in the custom options?  Do you just add 'dev "tunX"' in the  semi-colon separated custom options field?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Yes, just in the semicolon separated list of custom options put

            dev tun99;
            

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.