Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issue with traffic shaping queues and limiters.

    Traffic Shaping
    2
    5
    118
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      meii
      last edited by

      Hey!

      I'm having an issue setting up traffic shaping queues along side a limiter using FQ_CoDel. Right now it seems like the firewall rules setup for the limiter and the traffic shaping queues are causing an issue since when I have the firewall rule active that applies FQ_CoDel it seems like it stops processing other rules and doesn't direct traffic in to corresponding traffic shaping queues that are directed by the traffic shaping firewall rules. When I have the FQ_CoDel rule disabled, traffic shaping works fine and I can see the queues being used under Status > Queues.

      I would like to have both the limiter and traffic shaping queues working at the same time but I can't seem to figure out how to set that up. I'm new to networking and pfsense, so if anyone has any ideas on what could help that would be a big help!

      I've setup the FQ_CoDel limiter using this tutorial https://youtu.be/o8nL81DzTlU?t=377 so the settings and the firewall rule are based on that. I've included a screenshot attachment of the order of my firewall rules not all are visible but the ones not visible at the bottom continue with the queue rules.

      firewall rules.png

      1 Reply Last reply Reply Quote 0
      • N
        NOCling
        last edited by

        Why 4 rule?
        If you use ICMP any rule on WAN as out roul, you need only 2 rule.

        That's how it looks with me:
        d9569f41-4cd1-42a8-9eae-8cc9b14175c5-image.png

        Netgate 6100 & Netgate 2100

        M 1 Reply Last reply Reply Quote 0
        • M
          meii @NOCling
          last edited by

          @NOCling

          I noticed that if I had this two rules e0691a7c-a053-4d32-8681-a98dd621cd92-image.png
          you could be able to ping my firewall from the internet which I don't want, so I set an inbound block rule for it, if that was what you were asking.

          1 Reply Last reply Reply Quote 0
          • N
            NOCling
            last edited by

            My rule is wan out, so nobody from WAN side can ping my Firewall.

            Look at your rule and my, you see there ist no fix Gateway set on your side.

            Netgate 6100 & Netgate 2100

            1 Reply Last reply Reply Quote 0
            • M
              meii
              last edited by

              Thanks! That worked for the ping issue.

              I managed to get the traffic shaping queues to work by modifying the rules and setting the traffic to outbound and adding the codel queues to the in and out pipes and then I set the main CoDel Queue rule below the traffic shaping rules.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post