Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Limiting CIFS traffic over RED tunnel

Hi there,

 

I'm trying to limit the bandwidth usage for the CIFS Protocol (445) between our different locations using QoS. We connect our locations through a RED tunnel, each one has an own LAN.

Why we need it:

We have on our central a 100M/100M internet connection, on one of our locations (call it Site1) we do have just 20M/20M, if we copy a file over UNC path from/to the site the whole bandwidth will be used and the site won't have enough bandwidth to use other services.

Interface configuration on Site1:

(All the interfaces have Limit uplink, Limit Downlink and Upload optimizer activated)

eht0: Local-LAN 192.168.15.0/24 - QoS Status on - 1024M/1024M

eth1: WAN-Connection Default GW - QoS Status on - 20M/20M

eth2 & eth3: have different local networks that need internet, they don't have anything

redc4: RED tunnel to the central 10.168.0.2/30 - QoS Status on - 20M/20M

Traffic selector configuration:

Source: 192.168.15.0/24

Service: CIFS(445)

Destination: Any

TOS/DSCP: Off

Bandwidth pool:

Bound to interface: eth0 (Local-LAN)

Bandwidth: 128kbit/s

Limit: 5120kbit/s

Traffic selector: "CIFS From Local-LAN to Any"

What I've tried:

I've also tried to bound the Bandwidth pool to the redc4 interface, but it doesn't work either. If I run "iftop -i eth0" or "iftop -i redc4" I see the connection between the to computers over the port 445, with "iftop -i eth1" I only see the connection through port 3400 (i suppose it's the RED tunnel), so I've discarded the possibility to bind the bandwidth pool on the WAN interface.

I think I don't really understand how it works maybe it isn't even possible to do what a want to do, do you have any tips on how to do this? I hope there is enough information to understand what I want to achieve and how our system is configured.

 

Best regards,

Alberto.

 

 



This thread was automatically locked due to age.
Parents
  • Hi Alberto and welcome to the UTM Community!

    I would not select Limit uplink/downlink unless you are paying for the connection by the volume of traffic passing.  I would not select 'Upload optimizer' unless you have no Bandwidth Pools using that interface (this will be the case if you use my suggestion below).  Rather than "Any" in your Traffic Selector, I would use a Network or Network Group containing the remote networks.

    Rather than putting your traffic selector in a Bandwidth Pool, use a Download Throttling rule on eth0.  To limit the traffic in the other direction, you will need similar rules for your local interfaces in Site 1 with an inverse Traffic Selector.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi Alberto and welcome to the UTM Community!

    I would not select Limit uplink/downlink unless you are paying for the connection by the volume of traffic passing.  I would not select 'Upload optimizer' unless you have no Bandwidth Pools using that interface (this will be the case if you use my suggestion below).  Rather than "Any" in your Traffic Selector, I would use a Network or Network Group containing the remote networks.

    Rather than putting your traffic selector in a Bandwidth Pool, use a Download Throttling rule on eth0.  To limit the traffic in the other direction, you will need similar rules for your local interfaces in Site 1 with an inverse Traffic Selector.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?