This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

application based traffic shaping has no effect?

Following this article: 

https://community.sophos.com/kb/en-us/123062

Application traffic shaping does not seem to have any effect at all.   

 

I've set a super low bandwidth limit for a policy I call "guest video" (very limited for testing purposes) 

 

 

Applied that policy to a specific application: (in this case I"ve applied it to netflix/youtube/amazon streaming)

 

then applied it to firewall rules:

 

I've tried this on both Captive portal networks and hotspot networks with no effect at all.   missing somthing?



This thread was automatically locked due to age.
Parents Reply Children
  • Log viewer shows traffic going through the correct rule.

    Current live connections show the traffic under the correct application and user. (for the captive portal at least, there is also traffic showing up under application as N/A i'm assuming this is the hotspot user) (for example USER-A watching youtube, live connections show traffic for this user, with MB for youtube streaming) 

    Diagnostics pertaining to speed, is it possible to view speed per user?  I can see WAN speed and interface, but there is other traffic on those ports, so it's difficult to see specifically what each user may be using. 

  • Hi,

    I have been fine-tuning some of my policies and checked them against what you have set.

    There is nowhere in your firewall rule where you are applying your policy, you need to change allow all to your limiting policy.

    Ian

  • Changing from "allow all" to an Application policy has no effect.   My understanding is that the filter policy and traffic shaping policy are handled differently.  The Sophos docs on how to set up application-based traffic shaping does not show the necessity to have an application control policy set. 

  • Try following https://community.sophos.com/kb/en-us/132436

    One thing you can test is to block the application and see if that has any effect. It might be that the application is not being detected, if that is the case you should open a support ticket.