Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

sophos xg firewall traffic shaping by ip its possible?

I have ip ranges or groups like

192.168.110.1-10  | Group A | Can use facebook | 20mb down, 5mb up

192.168.110.11-254 | Group B | No service | 0mb down, 0mb up

192.168.111.1-254 | Group C | Service without social networks | 10mb down, 2mb up

(this groups are for test and examples)

So, thats what i want to make, actually the rules for deny or not the service are ready, but im trying now how to set up the traffic shaping, but i dont know how to make it possible, right now, i have seen this, but it doesnt work, it let me surface to any speed that has my router.

 

  (this rule is only for the ips 192.168.111.1-254)

 

Thanks for all the help :)

 



This thread was automatically locked due to age.
  • I know your addresses are not your real ones, not that matters behind a firewall with NAT, but your netmask should be 255.255.255.0.

    So how do each of the DHCP groups get to the internet, are they on their own LAN (or vlan). You haven't put the rules in the post.

  • Hi Mike,

    This setup is possible, you need to configure separate FW-rule for each range of IP address and define explicit Web and Application Filter along with QoS(traffic shaping) associated with it.

    Suppose, FW-rule: LAN(x.x.x.x) >ANY> WAN > WEB/APP Filter (traffic shapping applied)

    Refer the link here, you will get a brief idea over this: community.sophos.com/.../123062

    Thanks

  •  Mike, QoS in XG is really good. What I immediately see as a problem is that you are defining too much bandwidth. The QoS bandwidth is defined in KB as in KILOBYTES and not kb as in kilobits. So to throttle 

    20 megabit/s define 2500KB/s and not 20000

    5 megabit/s define 625KB/s and not 5000

    There have been a few feature requests to change everything into kb (kilobits) like it should be, lets see if they fix it in v17.