Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic shaping for all connections except company email server

    Traffic Shaping
    4
    9
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      ast
      last edited by

      hi!

      We have pfsense box in the office and we use traffic shaping to limit the bandwidth for some clients, just wondering, can we set a firewall rule to NOT limit the connection of some clients connection to  email servers?  Email servers can be google mail server, yahoo mail or our own domain email.

      TIA!

      ast

      1 Reply Last reply Reply Quote 0
      • A
        ast
        last edited by

        Anyone can help me? :)

        1 Reply Last reply Reply Quote 0
        • N
          Nullity
          last edited by

          It's seemingly a very simple thing to accomplish.

          What have you tried so far and what were the problems you encountered?

          Please correct any obvious misinformation in my posts.
          -Not a professional; an arrogant ignoramous.

          1 Reply Last reply Reply Quote 0
          • A
            ast
            last edited by

            I'm able to traffic shape some clients, but its for all their connections.  I want to exclude our office email server (mail.xxxxxxx.com) from the limiter for faster downloading and sending of emails.

            1 Reply Last reply Reply Quote 0
            • A
              ast
              last edited by

              Any tip on how to do this simple thing? :)

              1 Reply Last reply Reply Quote 0
              • jahonixJ
                jahonix
                last edited by

                @Nullity:

                …what were the problems you encountered?

                Setting up a matching firewall rule on top of the others?

                1 Reply Last reply Reply Quote 0
                • A
                  ast
                  last edited by

                  @jahonix:

                  @Nullity:

                  …what were the problems you encountered?

                  Setting up a matching firewall rule on top of the others?

                  I need to put the "allow connection to company email server rule" on top of the traffic shaper rule?

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    You need to place a rule above the rule that puts the traffic in the queues. It should pass traffic from the local addresses you want to exempt with a destination of the mail server address. On that rule you can either set another higher priority queue or no queue at all since you're using limiters.

                    You probably want to make a host alias using the mail host names for google and yahoo. such as hosts smtp.gmail.com, pop.gmail.com, and imap.gmail.com and whatever yahoo is doing these days. Webmail will be more difficult to identify the traffic.

                    Anyway, you figure out how to identify the traffic you want to exempt from the limiters and pass that traffic without setting a limiter above the limiter rules.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • A
                      ast
                      last edited by

                      Thanks a lot for the advice, I have blocked webmail services via firewall rule already.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.