Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Shaping HTTPS uploads

    Scheduled Pinned Locked Moved Traffic Shaping
    14 Posts 4 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      Probably best to post screen shots of the rule(s) and the queue setups.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • M
        MaxPF
        last edited by

        Here are the screenshots of the floating rule and the queues created by the wizard. 192.168.1.25 in on LAN and is going out the net on WAN.

        pf1.PNG
        pf1.PNG_thumb
        pf2.PNG
        pf2.PNG_thumb
        pf3.PNG
        pf3.PNG_thumb
        pf4.PNG
        pf4.PNG_thumb

        1 Reply Last reply Reply Quote 0
        • N
          Nullity
          last edited by

          Can you post the floating & LAN rules list?

          I try to avoid floating rules unless they are required.

          Can you use a LAN interface rule instead? (Just use "PASS" instead of "MATCH".)

          Please correct any obvious misinformation in my posts.
          -Not a professional; an arrogant ignoramous.

          1 Reply Last reply Reply Quote 0
          • M
            MaxPF
            last edited by

            I tried to set the rule on the LAN using Pass just above the standard rule to allow LAN traffic out. HTTPS uploads still go to qDefault

            Capture2.PNG
            Capture2.PNG_thumb
            Capture.PNG
            Capture.PNG_thumb

            1 Reply Last reply Reply Quote 0
            • M
              MaxPF
              last edited by

              One more screenshot showing that in the logs the floating rule is actually triggered while uploading to Google Drive (in this case), but the traffic is not sent to the correct queue

              Capture3.PNG
              Capture3.PNG_thumb

              1 Reply Last reply Reply Quote 0
              • S
                sideout
                last edited by

                If you are using floating rules , use WAN for the interface.

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Can't use WAN for the interface and match on a LAN address after NAT.

                  Just so we know exactly what we're looking at, is LAN's qOthersLow just cropped off of that last Status > Queues you posted? I know it's in the shaper config  further up but… - Nevermind. That's a select list not freeform text where you set the queue.

                  Something else has to be matching the traffic and not setting the queue.

                  You running squid by any chance?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • M
                    MaxPF
                    last edited by

                    sideout suggestion worked! Changing the floating rule to use WAN with direction out, source IP set to the host on the LAN and HTTPS as destination port did the trick. I thought I tried that combination before, but apparently I didn't. Now whenever I upload from 192.168.1.25 to GDrive for example I can finally see the traffic going on the qOthersLow queue on the WAN interface.

                    Thanks for the help everybody!  :D

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      That doesn't make any sense to me.

                      When you match on WAN out NAT has already happened and source address is the WAN address (by default).

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • M
                        MaxPF
                        last edited by

                        @Derelict:

                        That doesn't make any sense to me.

                        When you match on WAN out NAT has already happened and source address is the WAN address (by default).

                        Strange or not, it works  :o

                        1 Reply Last reply Reply Quote 0
                        • S
                          sideout
                          last edited by

                          I generally set the direction to both on Floating rules when choosing direction and WAN as the interface.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.