Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Limit new connections

    Scheduled Pinned Locked Moved Traffic Shaping
    4 Posts 4 Posters 702 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nandoiin
      last edited by

      Good morning, Mrs.

      Has anyone done or knows how to limit any and all connection at a specific speed?

      Example: I have a web server that is accessed via NAT on port 443. Each connection, depending on the procedure done, uses 100Kb, 500Kb, 2Mb, 5Mb ... Is there any way to limit any new connection at a maximum speed of 1Mbps?

      I know that if I create several rules, put IP in each source, create in traffic shaper and add in Advanced In / Out Pipe the speed I want, it will work ... But I have many different IPs connecting and most are not fixed. .. Does anyone know how I can do this bandwidth control?

      My problem is that I have 10Mb and there are times that only 2 clients (monitored via iftop and are always different) reach 10Mb and the next requests are slow / timeout depending on the time they are requesting data.

      1 Reply Last reply Reply Quote 0
      • H
        Harvy66
        last edited by

        Slow requests and timeouts are due to bufferbloat, not "saturation". You don't need to limit the bandwidth of the connections, you just need to make sure your link doesn't have a backlog of packets.

        Try enabling FairQ shaper on your WAN, then set the Default queue to use Codel. This is very easy to do and may be good enough. Once 2.4.4 is released, look into fq_Codel.

        There is hope for a near perfect turn-key shaping called "cake". One of the main features is near perfect bandwidth distribution and latency isolation among different IP addresses. But don't hold your breath. They've been near release for a few years now. A few 11th hour features caused a bunch of regressions and they've been trying to fix the issues since.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Or don't serve up connections to the public internet on such a small pipe - 10mbps.. Fine if your wanting to watch paint dry I guess ;)

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Limiting at the web server itself might also be possible.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.