This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Limiting bandwidth on a VLAN does not work

Hi,

I have created a Guest VLAN (Port1.2) with a DHCP (10.0.0.0/24) to isolate the visitors connected on Unify APs. Unify APs Guest SSID is pointing to this Guest VLAN. ipconfig from a guest computer gives me : 10.0.0.2. So everything works fine and I get internet access.

Now I want to limit the bandwidth for all users on this Guest VLAN. So I set up a traffic shaping policy (100Mbps is for test purpose :) ) :

Then I put new rule on the top of firewall rules:

  • WAN-ANY >> LAN-Port1.2
  • Traffic shaping policy : Limited Share Bandwidth

But download bandwidth is not limited on my guest computer and all traffic goes though default firewall rules (bottom one).

What am I doing wrong?



This thread was automatically locked due to age.
Parents Reply Children
  • Here are an overview of the firewall rules. I am using a Guest VLAN (Port1.2) but the traffic goes though rule ID 2.

    I tested the traffic shaping policy on rule ID 2 and it works. So no issue with the policy settings.

    Guest rule advanced section:

      

    Tks!

  • I found the issue ( or should I call it a bug? )...

    In my firewall rule, I was using as a source : LAN, Port1.2

    I've replaced the Port1.2 by it associated network (10.0.0.0/24) and it works.

     

    So why is Port1.2(VLAN)  being seen as Port1(LAN)? Physically they are the same, but they are two distinct networks.

  • Because it is a limitation of the current XG. You could even give it a network name and that would work.

    I haven't seen any release plans for a fix or improvement. There are a number of similar issues with networking and being able to select objects.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • They should at least remove the VLAN port selection for now until they fix this. I am surely not the only one using VLANs and policies.

    Tks for the info. I'll keep that in mind. 

  • No, we all tried it and failed. I haven't tried again since early in v17.0.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.