Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic Shaper w Codel not doing a thing in 2.5

    Scheduled Pinned Locked Moved Traffic Shaping
    32 Posts 5 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      ryk48 @NOCling
      last edited by

      @nocling yeah that’s why I found it strange no matter what setting i changed it didn’t seem to have any affect.

      I wonder if it has anything to do or doesn’t work well with HA being setup because I have two pfsense boxes running in case one goes down the other picks up. They are vms on different PCs.

      R 1 Reply Last reply Reply Quote 0
      • R
        ryk48 @ryk48
        last edited by

        @ryk48 I’m running 2.5.1

        1 Reply Last reply Reply Quote 0
        • M
          MagikMark
          last edited by

          For Q management use "Tail Drop" instead, as "Codel" has some bugs on it. The result is pretty much the same.

          For scheduler use "FQ-Codel"

          R 1 Reply Last reply Reply Quote 0
          • R
            ryk48 @MagikMark
            last edited by

            @magikmark would i set this for both the limiter and its queue? When i set the queue to taildrop it doesn't like that ECN is enabled.

            R 1 Reply Last reply Reply Quote 0
            • R
              ryk48 @ryk48
              last edited by

              @ryk48 assuming what i said was correct, i made those changes and did a dslreports test and once again made zero difference, like it might as well have never been enabled. With my bandwidth set so low i would have expected to see a significant drop in bandwidth when i ran the test, that way id know its actually doing something and I can set the bandwidth back to something more appropriate but no change.

              T 1 Reply Last reply Reply Quote 0
              • T
                tomashk @ryk48
                last edited by tomashk

                @ryk48 In the past I observed that the following made big difference while running test on dslreports:

                • testing on wi-fi vs cable
                • computer (so poor CPU, NIC and other parts)
                • antivirus software - even if disabled there was some strange buffering that completely break results - uninstalling has given me normal results
                • bufferbloat introduced by ISP's devices/software (it might be hard to change anything if your ISP doesn't know what to do to provide good connection :) )

                I'm just thinking aloud and mention what I have seen when I have been trying to fix my bufferbloat.

                R 1 Reply Last reply Reply Quote 0
                • R
                  ryk48 @tomashk
                  last edited by

                  @tomashk computer is recent and fairly quick, I only run the browser when doing the test. It’s connected via 10gbit fiber to my switch, I’ve got mediacom 1000/50 cable service on a docsis 3.1 modem. I don’t run AV other than built in windows defender. Back when I had 300-500 mbit service the limiters used to work so I’m not sure what’s different now or why no matter what setting I change it seems to have no effect. Not sure if there’s a log I can check to see if it’s even using the limiters.

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tomashk @ryk48
                    last edited by

                    @ryk48 to see if limiters are doing anything go to Diagnostics -> Limiter Info

                    214aa59d-bf39-47ce-b44f-f2208117a91f-image.png

                    Lines with red arrows don't appear if limiter/fq_codel is not doing anything. Or at least I understand it like that :)

                    R 1 Reply Last reply Reply Quote 0
                    • R
                      ryk48 @tomashk
                      last edited by

                      @tomashk said in Traffic Shaper w Codel not doing a thing in 2.5:

                      o Diagnostics -> Limiter Info

                      here is what i have:

                      Limiters:
                      00001: 10.000 Mbit/s 0 ms burst 0
                      q131073 1000 sl. 0 flows (1 buckets) sched 65537 weight 0 lmax 0 pri 0 droptail
                      sched 65537 type FIFO flags 0x0 0 buckets 0 active
                      00002: 1.000 Mbit/s 0 ms burst 0
                      q131074 1000 sl. 0 flows (1 buckets) sched 65538 weight 0 lmax 0 pri 0 droptail
                      sched 65538 type FIFO flags 0x0 0 buckets 0 active

                      Schedulers:
                      00001: 10.000 Mbit/s 0 ms burst 0
                      q00001 50 sl. 0 flows (1 buckets) sched 1 weight 0 lmax 0 pri 0 droptail
                      sched 1 type FQ_CODEL flags 0x0 0 buckets 0 active
                      FQ_CODEL target 5ms interval 100ms quantum 1514 limit 10240 flows 1024 ECN
                      Children flowsets: 1
                      00002: 1.000 Mbit/s 0 ms burst 0
                      q00002 50 sl. 0 flows (1 buckets) sched 2 weight 1 lmax 0 pri 0 droptail
                      sched 2 type FQ_CODEL flags 0x0 0 buckets 0 active
                      FQ_CODEL target 5ms interval 100ms quantum 1514 limit 10240 flows 1024 ECN
                      Children flowsets: 2

                      Queues:
                      q00001 50 sl. 0 flows (1 buckets) sched 1 weight 0 lmax 0 pri 0 droptail
                      q00002 50 sl. 0 flows (1 buckets) sched 2 weight 1 lmax 0 pri 0 droptail

                      T 1 Reply Last reply Reply Quote 0
                      • T
                        tomashk @ryk48
                        last edited by

                        @ryk48 While looking at limiter information, try running some speed test in the background. Lines that I showed on my screenshot disappear if there is no "heavy lifting" done by the limiters. If said lines don't show up during speed test, then it is indicating that fq_codel is not used.

                        (somebody please correct me if I'm wrong at any point - but that way of thinking helped me for my troubleshooting)

                        R 1 Reply Last reply Reply Quote 0
                        • M
                          MagikMark
                          last edited by

                          Do the ff:

                          Dashboard -> Firewall -> Traffic Shaper -> New Limiter -> New Limiter

                          Tick: Enable Limiter and its Children
                          Name: ISP-Download-Speed
                          Bandwith: 100 Mbps
                          Description: ISP Download Speed
                          Queue: Tail Drop
                          Scheduler: FQ-Codel
                          Tick: ECN

                          SAVE

                          Scheduler: Quantum=300 Limit=20480 Flows=65535

                          SAVE

                          ADD NEW QUEUE

                          Tick: Enable this queue
                          Name: WAN-Upload-Queue
                          Desciption: WAN Upload Queue
                          Queue: Tail Drop

                          SAVE

                          +NEW LIMITER

                          Tick: Enable Limiter and its Children
                          Name: ISP-Upload-Speed
                          Bandwith: 100 Mbps
                          Description: ISP Upload Speed
                          Queue: Tail Drop
                          Scheduler: FQ-Codel
                          Tick: ECN

                          SAVE

                          Scheduler: Quantum=300 Limit=20480 Flows=65535

                          ADD NEW QUEUE

                          Tick: Enable this queue
                          Name: WAN-Download-Queue
                          Desciption: WAN Download Queue
                          Queue: Tail Drop

                          SAVE

                          Firewall->Rules->Floating

                          ADD

                          Action: Match
                          Tick: Apply this action immediately on match
                          Interface: WAN
                          Direction: In
                          Address Family: IPv4
                          Protocol: Any
                          Description: Incoming traffic Queue

                          ADVANCE OPTIONS

                          In/Out Pipe: Wan-Upload-Queue Wan-Download-Queue

                          SAVE

                          ADD BELOW

                          Action: Match
                          Tick: Apply this action immediately on match
                          Interface: WAN
                          Direction: Out
                          Address Family: IPv4
                          Protocol: Any
                          Description: Outgoing traffic Queue

                          ADVANCE OPTIONS

                          In/Out Pipe: Wan-Download-Queue Wan-Upload-Queue

                          SAVE

                          R 1 Reply Last reply Reply Quote 0
                          • R
                            ryk48 @tomashk
                            last edited by

                            @tomashk when doing a speedtest i don't get that line in the limiter info section.

                            1 Reply Last reply Reply Quote 0
                            • R
                              ryk48 @MagikMark
                              last edited by

                              @magikmark Did you mean to have the upload que as part of the download limiter which is backwards from what ive read to set? Same story for firewall floating rules, did you intend to have it set as wandownq | wanupq instead of the other way around for the wan interface on the outbound direction?

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                MagikMark @ryk48
                                last edited by MagikMark

                                @ryk48 That is how pfsense designed it. When adding queue, you need to do it in the point of view of the interface

                                R 1 Reply Last reply Reply Quote 0
                                • R
                                  ryk48 @MagikMark
                                  last edited by

                                  @magikmark ok, deleted all my limiters and the floating fw rule and did as suggested. I did notice when looking at the status filter reload at the end i have:
                                  There were error(s) loading the rules: /tmp/rules.debug:21: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [21]: table <bogonsv6> persist file "/etc/bogonsv6"

                                  checked the limiter info again while running a speedtest and again no difference at all and no line like above red arrows

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    MagikMark
                                    last edited by MagikMark

                                    Under fq_codel scheduler, delete all entries. This will set everything to default

                                    This will help you as well:

                                    https://forum.netgate.com/topic/112527/playing-with-fq_codel-in-2-4/1045

                                    R 1 Reply Last reply Reply Quote 0
                                    • R
                                      ryk48 @MagikMark
                                      last edited by

                                      @magikmark that did it! now seems to be working as expected! Thanks! It seems like something was stuck or corrupt which may have caused that issue.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.