Multiple Limiters on 2.4.2



  • I have a pfsense firewall setup in Bridge mode.  I'm bridging the WAN to LAN.  The bridge works exactly as expected.  I'm using the transparent bridge to limit bandwidth based on various subnets.

    I have a few limiters setup

    (75mbps / 10mbps) (download / Upload) <= this one has some queues
    (6mbps / 2mpbs) (download-kids / upload-kids).  Mask NONE is selected for both limiters here.

    When I create a firewall rule for the kids subnet 10.0.10.1/24 and assign the in/out Pipe of (upload-kids/download-kids) No traffic passes.  I cannot ping the gateway or the internet.

    However, when I apply the in/out Pipe of (upload / download) or a queue under these limiters (upload-kids-weight / download-kids-weight) I'm able to pass traffic just fine.  Any thoughts on why this second set of limiters will not work?

    ![Screen Shot 2018-03-25 at 8.46.31 AM.png](/public/imported_attachments/1/Screen Shot 2018-03-25 at 8.46.31 AM.png)
    ![Screen Shot 2018-03-25 at 8.46.31 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2018-03-25 at 8.46.31 AM.png_thumb)
    ![Screen Shot 2018-03-25 at 8.47.02 AM.png](/public/imported_attachments/1/Screen Shot 2018-03-25 at 8.47.02 AM.png)
    ![Screen Shot 2018-03-25 at 8.47.02 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2018-03-25 at 8.47.02 AM.png_thumb)



  • Hi,

    I have a couple ideas/questions:

    1)  If you create a default queue underneath both the upload-kids and download-kids limiters and apply those queues to the firewall rules, are you able to pass traffic?
    2)  If you set the mask of the download-kids limiter to "Destination addresses" and the mask of the upload-kids limiter to "Source addresses", are you able to pass traffic just using the limiters (vs. having to create queues underneath them)?

    Hope this helps.



  • Thank you for your reply.  I was thinking the same thing, so I tried both previously.  I tried it again just now and both failed.

    I also read somewhere where "-" could create issues in the name.  So I removed the "-" from all limiter names and queue names.  That did not help either.

    When I changed the mask to Source / Destination I also tried /24 and /32 for both.  Neither worked.  I tried that for both the limiters and queues for those limiters.

    ![Screen Shot 2018-03-25 at 10.16.03 AM.png](/public/imported_attachments/1/Screen Shot 2018-03-25 at 10.16.03 AM.png)
    ![Screen Shot 2018-03-25 at 10.16.03 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2018-03-25 at 10.16.03 AM.png_thumb)



  • check : https://forum.pfsense.org/index.php?topic=126637.0
    Im trying to do sort of the same thing. although in my case it works but like with yours the queues are not working as my mind thinks they should


Log in to reply