Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unsure How to Configure Limiter

    Scheduled Pinned Locked Moved Traffic Shaping
    19 Posts 5 Posters 4.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by

      @Nullity:

      Site 1 is where the backup server is? (I am unclear about your network topolgy.)

      Yes, it is.

      If so, yeah, you would need to shape the download at that end,

      This is what I was going to do with the Limiters of the Traffic shaper.
      I am just unsure how this all works together regarding the correct configuration. Currently it does not limit at all.
      So you say I should configure traffic shaper Seems to be possible, but as you mention it is far away of being perfect. I had a look what the pfSense docs say regarding HFSC:

      It can be very effective for VoIP on links that degrade quickly, such as 3G/4G, but it can be complex to configure and tweak for proper operation. 
      

      For PRIQ it says:

       Lower priority queues can be completely starved for bandwidth easily.
      

      Which is bad as I need to have the backup to continue any time. Otherwise it would re-start from scratch…
      And CBQ limits trafffic non-dynamically. Bad idea.

      Still, it loks like I can not use traffic shaper.

      So I am back at my first question: How to configure properly to have it up and running?

      I thought you could match individual traffic types with firewall rules on the OpenVPN interface itself.

      No way. Only physical interfaces.

      1 Reply Last reply Reply Quote 0
      • N
        Nullity
        last edited by

        @knebb:

        No way. Only physical interfaces.

        Are you sure?

        Please correct any obvious misinformation in my posts.
        -Not a professional; an arrogant ignoramous.

        1 Reply Last reply Reply Quote 0
        • ?
          A Former User
          last edited by

          @Nullity:

          @knebb:

          No way. Only physical interfaces.

          Are you sure?

          Pretty much, yes. See attached image. There might be a possibility to configure them on virtual interfaces, but this is not possible with the pfSense GUI. And I am not going on the command line (as these settings will be hidden when you do troubleshooting later).

          limiter.png
          limiter.png_thumb

          1 Reply Last reply Reply Quote 0
          • N
            Nullity
            last edited by

            @knebb:

            @Nullity:

            @knebb:

            No way. Only physical interfaces.

            Are you sure?

            Pretty much, yes. See attached image. There might be a possibility to configure them on virtual interfaces, but this is not possible with the pfSense GUI. And I am not going on the command line (as these settings will be hidden when you do troubleshooting later).

            I said firewall rules, not traffic-shaping (which your image shows).

            You may need to do some reading about how VPN, firewall rules, and traffic-shaping queues/limiters work together…

            Please correct any obvious misinformation in my posts.
            -Not a professional; an arrogant ignoramous.

            1 Reply Last reply Reply Quote 0
            • ?
              A Former User
              last edited by

              @Nullity:

              I said firewall rules, not traffic-shaping (which your image shows).

              Ok, misunderstood.
              Still, with firewall rules I can not limit my traffic. I can select it and let it pass or block/ drop it.

              You may need to do some reading about how VPN, firewall rules, and traffic-shaping queues/limiters work together…

              This is exactly where I need help. As I wrote in my initial post I did some reading.

              My point is that I do not know why it is not working (where I assume I did some misconfiguration). So what I have is a firewall rule on the LAN interface which matches my traffic (destination host is my backup host). On the advanced options of this rule I configured the In/ Out pipe to use the limiter rules.
              The limiter itself is configured for an IN and an OUT pipe where the limits are defined.

              But still- the backup server consumes 10Mbit/sec instead of configured 1Mbit/s.

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                Still, with firewall rules I can not limit my traffic. I can select it and let it pass or block/ drop it.

                Expand the Advanced section and look for In / Out Pipe.  This is where you direct traffic into a limiter.

                1 Reply Last reply Reply Quote 0
                • N
                  Nullity
                  last edited by

                  First, confirm about your firewall rule is catching the proper traffic. Once that is confirmed you can begin to deal with where that traffic is assigned (limiters or queues).

                  Personally, I think limiters are best used for other things, like dynamic sharing among IPs.
                  Queues, like HFSC, CBQ (with borrowing), or FAIRQ are what I would use here.

                  Please correct any obvious misinformation in my posts.
                  -Not a professional; an arrogant ignoramous.

                  1 Reply Last reply Reply Quote 0
                  • J
                    jbourn1907
                    last edited by

                    How to read this limiter logs?

                    Thanks.

                    queue.PNG
                    queue.PNG_thumb

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      Please don't hijack someone else's thread with unrelated stuff.  Start a new thread.

                      1 Reply Last reply Reply Quote 0
                      • J
                        jbourn1907
                        last edited by

                        Sorry but i think this thread is still related to limiter.
                        I configure limiter and I don't know how to read this details so I think anyone here can help me about this.

                        Thanks and sorry for this.

                        1 Reply Last reply Reply Quote 0
                        • KOMK
                          KOM
                          last edited by

                          Every question in this forum has to do with the shaper or limiter.  This post is specifically about how to configure.  You want to know how to read a log.  Not the same thing.  Start your own thread.

                          1 Reply Last reply Reply Quote 0
                          • J
                            jbourn1907
                            last edited by

                            Ok. Thank you.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.