  • Hi all,

    I am coming from a fortinet world.  Is this possible?

    2 physical ports
    WAN 10x10 upload & download
    I would like to setup traffic shaping based on VLAN and usage.

    I would like to have a guaranteed 5mbps for both VLANS, but have the ability to use a max of 9mbps if the bandwidth is available.  Once other VLAN needs bandwidth, it will take if from the VLAN that is using it and regulate it back to 5mbps max.
    Is this possible with pfsense?


  • Short answer, no. Interfaces cannot share bandwidth. Longer answer, maybe with some strange configurations to make your two interfaces share a single upstream interface and shaping the upstream.

    It essentially requires two pfSense nodes. One to shape out one transit interface and probably perform NAT/WAN rule duties and one on the inside to firewall the various segments. If you don't need to firewall the inside segments an inside layer 3 switch would work too.

    Along these lines does HFSC shaping work on a lagg? I've never tried it.

  • If it does technically work on LAGG, it definitely would not be able to have strict guarantees about packet timings without knowing which interface a packet will get scheduled.

