Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Application control QoS rules stop working till reboot

Hi, I have a firewall policy for clientless users that applies QoS to each user but at the same time have a policy to throttle youtube traffic. The problem is that everything works correctly for about 24 hours and then when I wake up in the morning, the application control part stops working. Disabling/enabling firewall policy doesn't work. If I reboot the firewall, everything works again.

The firewall keeps categorizing the apps correctly so that is not the problem. How can I restart the QoS daemon without restarting XG?

Here is the firewall policy

Here is when the QoS is working correctly with traffic shaping policy 25 (application control)

This is when it stops working and defaults to the user based QoS policy

Any hints???

Regards
Bill



This thread was automatically locked due to age.
  • Bill,

    I configured the QoS yesterday and 24 hours are gone. My QoS policy is still working on Youtube Traffic for my clientless user. I have moved the Policy rule at the top with only that clientless user.

  • Yeah I think I have narrowed down the bug. I changed the application control settings like below

    If you apply application control while allowing all applications, it keeps working. However, when application control is also applied at the same time, it stops working.

    Thanks for testing it out and appreciate all your help

    Regards

    Bill

  • Bill,

    I always prefer to create custom as possible. In my case I created a Youtube Application Filter and it worked.

    Thanks anyway for your testing too. This will help other users.

  • I had created a new application filter with allow all template. Then I was blocking twitter and apple OTA updates to see how XG was behaving. You are of course correct that allowing only what is needed is the best way to create policies.

     

    In any case, now that I know that the base functionality works, I may promote XG to my home firewall for internal clients[;)] Still using UTM9 as parameter firewall for WAF and email[8-|] 

    Thanks again , , and  for all the help you guys provide to the community. You guys are all great!

    Regards

    Bill