I'm really struggling to get QoS right. It seems really hard to come up with something that doesn't end up overloading the uplink and rendering the WAN link unresponsive.
Total WAN bandwidth is around 20mbit/second down, 1mbit/second up.
If I put all LAN -> WAN traffic in one rule I can put a shared limit of 2800kbit/second down and 120kbit/second up, which is just below the point where the link is saturatedand that keeps the uplink queues to a minimum and responsiveness is good, but then if I want to put different rules for different traffic it gets really hard to micromanage.
I can tolerate the LAN -> WAN thing for now as the result gives tolerable latency, but we also have some wireless hotspots that we want to manage too. I want to give them a chunk of the available bandwidth, but when it comes to choosing a shaping rule I can only choose a shaping policy that has "Individual" limits, and does not have separate limits for upload and download. I can modify the resulting firewall rule directly and choose the shaping policy I want, but that seems like i'm breaking some rule somewhere.
But even after that, i would like LAN->WAN traffic to be able to borrow from unused hotspot bandwidth, but that just doesn't seem possible.
Is Sophos XG unsuitable for a network with an asymmetric WAN link? (or multiple WAN links for that matter)?
Thanks
James
This thread was automatically locked due to age.