• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Shaping HTTPS uploads

Scheduled Pinned Locked Moved Traffic Shaping
14 Posts 4 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    MaxPF
    last edited by May 8, 2016, 10:08 PM

    Thanks for the reply. I tried both your suggestions and still the traffic goes to the qDefault. I enabled logging on the rule and I can see it being triggered, but for some reason the https traffic is not going in the qOthersLow as I want it to.

    Is there any built in rule for https traffic that overrides custom rules? I haven't tweaked any of the wizard generated settings. It should be pretty straight forward.

    1 Reply Last reply Reply Quote 0
    • D
      Derelict LAYER 8 Netgate
      last edited by May 8, 2016, 10:18 PM

      Probably best to post screen shots of the rule(s) and the queue setups.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • M
        MaxPF
        last edited by May 9, 2016, 1:20 AM

        Here are the screenshots of the floating rule and the queues created by the wizard. 192.168.1.25 in on LAN and is going out the net on WAN.

        pf1.PNG
        pf1.PNG_thumb
        pf2.PNG
        pf2.PNG_thumb
        pf3.PNG
        pf3.PNG_thumb
        pf4.PNG
        pf4.PNG_thumb

        1 Reply Last reply Reply Quote 0
        • N
          Nullity
          last edited by May 9, 2016, 1:29 AM

          Can you post the floating & LAN rules list?

          I try to avoid floating rules unless they are required.

          Can you use a LAN interface rule instead? (Just use "PASS" instead of "MATCH".)

          Please correct any obvious misinformation in my posts.
          -Not a professional; an arrogant ignoramous.

          1 Reply Last reply Reply Quote 0
          • M
            MaxPF
            last edited by May 9, 2016, 1:07 PM

            I tried to set the rule on the LAN using Pass just above the standard rule to allow LAN traffic out. HTTPS uploads still go to qDefault

            Capture2.PNG
            Capture2.PNG_thumb
            Capture.PNG
            Capture.PNG_thumb

            1 Reply Last reply Reply Quote 0
            • M
              MaxPF
              last edited by May 10, 2016, 5:12 PM

              One more screenshot showing that in the logs the floating rule is actually triggered while uploading to Google Drive (in this case), but the traffic is not sent to the correct queue

              Capture3.PNG
              Capture3.PNG_thumb

              1 Reply Last reply Reply Quote 0
              • S
                sideout
                last edited by May 10, 2016, 6:09 PM

                If you are using floating rules , use WAN for the interface.

                1 Reply Last reply Reply Quote 0
                • D
                  Derelict LAYER 8 Netgate
                  last edited by May 11, 2016, 12:13 AM May 11, 2016, 12:01 AM

                  Can't use WAN for the interface and match on a LAN address after NAT.

                  Just so we know exactly what we're looking at, is LAN's qOthersLow just cropped off of that last Status > Queues you posted? I know it's in the shaper config  further up but… - Nevermind. That's a select list not freeform text where you set the queue.

                  Something else has to be matching the traffic and not setting the queue.

                  You running squid by any chance?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • M
                    MaxPF
                    last edited by May 11, 2016, 1:10 PM

                    sideout suggestion worked! Changing the floating rule to use WAN with direction out, source IP set to the host on the LAN and HTTPS as destination port did the trick. I thought I tried that combination before, but apparently I didn't. Now whenever I upload from 192.168.1.25 to GDrive for example I can finally see the traffic going on the qOthersLow queue on the WAN interface.

                    Thanks for the help everybody!  :D

                    1 Reply Last reply Reply Quote 0
                    • D
                      Derelict LAYER 8 Netgate
                      last edited by May 12, 2016, 12:17 AM

                      That doesn't make any sense to me.

                      When you match on WAN out NAT has already happened and source address is the WAN address (by default).

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • M
                        MaxPF
                        last edited by May 12, 2016, 3:08 PM

                        @Derelict:

                        That doesn't make any sense to me.

                        When you match on WAN out NAT has already happened and source address is the WAN address (by default).

                        Strange or not, it works  :o

                        1 Reply Last reply Reply Quote 0
                        • S
                          sideout
                          last edited by May 12, 2016, 4:10 PM

                          I generally set the direction to both on Floating rules when choosing direction and WAN as the interface.

                          1 Reply Last reply Reply Quote 0
                          14 out of 14
                          • First post
                            14/14
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received