Be aware: HFSC QoS
-
Hello,
I'm writing this, but I didn't discovered this in pfSense… yet.
Recently, one of our routers using HFSC script for 2 x WAN config had huge problem.
Rules are simply based on ports. There are: interactive, voip, browsing classes.
This was working config a looong time, ping from both WANs was 5-20 ms, but recently we received it's growing up to 2000 ms.
I discovered that this was caused by some client application hitting SSH port "22" which was in Interactive class (like some download manager). This caused queue to be full, resoulting in high latency times.
I'm just wondering.. how pfSense matches connections for QoS engine? Is it port-based?
I remember that Layer7 protocol definition files can do this, but someone told me this isn't always working.I don't know exacly how to do this, but in my opinion matching should be done using port+layer7 definitions.. to avoid situations like this.
-
You can test yourself.
The wizards match based on ports.The layer7 matching cannot be made to be the same for 2 installations so you can do it yourself.
AFAIK layer7 shaping works!