Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Are these floating rules correct?

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 678 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      Upper Deck
      last edited by

      Hi there,

      I'm trying to optimize my network, but I'm a little confused about the floating rules. My intention is to lower the traffic priority of the local P2P server, and to raise the traffic priority of local OpenVPN server and remote RDP. Are these floating rules correct?

      Thank you.

      pic.png

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        That rule for the OpenVPN server should be inbound on WAN with a destoination port of 1194 if you are trying to catch traffic from clients connecting in to it.

        Steve

        U 1 Reply Last reply Reply Quote 0
        • U
          Upper Deck @stephenw10
          last edited by

          Hi @stephenw10

          Thank you for your reply.

          Should I change the LAN P2P SERVER to "Destoination" on WAN interface too? Now it has both inbound and outbound (any) directions.

          S 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Probably not. You want that to match outbound since the server is opening the connections to external addresses.
            If the server also accepts connections from external IPs then, yes, you would want additional rules to match that traffic too.

            Steve

            1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @Upper Deck
              last edited by

              @upper-deck If you're finding traffic isn't getting into the queues as expected (Status/Queues) I suggest finding the state for the IP (Diagnostics/States). For example, downloads from a web server are generally an incoming connection to the web server and the download is merely the response.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.