• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Traffic shaping for all connections except company email server

Scheduled Pinned Locked Moved Traffic Shaping
9 Posts 4 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    ast
    last edited by Jul 8, 2017, 9:32 AM

    hi!

    We have pfsense box in the office and we use traffic shaping to limit the bandwidth for some clients, just wondering, can we set a firewall rule to NOT limit the connection of some clients connection to  email servers?  Email servers can be google mail server, yahoo mail or our own domain email.

    TIA!

    ast

    1 Reply Last reply Reply Quote 0
    • A
      ast
      last edited by Jul 19, 2017, 10:16 AM

      Anyone can help me? :)

      1 Reply Last reply Reply Quote 0
      • N
        Nullity
        last edited by Jul 19, 2017, 11:20 AM

        It's seemingly a very simple thing to accomplish.

        What have you tried so far and what were the problems you encountered?

        Please correct any obvious misinformation in my posts.
        -Not a professional; an arrogant ignoramous.

        1 Reply Last reply Reply Quote 0
        • A
          ast
          last edited by Jul 19, 2017, 1:50 PM

          I'm able to traffic shape some clients, but its for all their connections.  I want to exclude our office email server (mail.xxxxxxx.com) from the limiter for faster downloading and sending of emails.

          1 Reply Last reply Reply Quote 0
          • A
            ast
            last edited by Jul 23, 2017, 4:49 AM

            Any tip on how to do this simple thing? :)

            1 Reply Last reply Reply Quote 0
            • J
              jahonix
              last edited by Jul 23, 2017, 5:50 PM

              @Nullity:

              …what were the problems you encountered?

              Setting up a matching firewall rule on top of the others?

              1 Reply Last reply Reply Quote 0
              • A
                ast
                last edited by Jul 24, 2017, 1:38 AM

                @jahonix:

                @Nullity:

                …what were the problems you encountered?

                Setting up a matching firewall rule on top of the others?

                I need to put the "allow connection to company email server rule" on top of the traffic shaper rule?

                1 Reply Last reply Reply Quote 0
                • D
                  Derelict LAYER 8 Netgate
                  last edited by Jul 24, 2017, 1:53 AM

                  You need to place a rule above the rule that puts the traffic in the queues. It should pass traffic from the local addresses you want to exempt with a destination of the mail server address. On that rule you can either set another higher priority queue or no queue at all since you're using limiters.

                  You probably want to make a host alias using the mail host names for google and yahoo. such as hosts smtp.gmail.com, pop.gmail.com, and imap.gmail.com and whatever yahoo is doing these days. Webmail will be more difficult to identify the traffic.

                  Anyway, you figure out how to identify the traffic you want to exempt from the limiters and pass that traffic without setting a limiter above the limiter rules.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • A
                    ast
                    last edited by Jul 24, 2017, 2:08 AM

                    Thanks a lot for the advice, I have blocked webmail services via firewall rule already.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received