Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Download throttling for limiting application bandwidth per client

Hello,

I'd like to limit bandwidth for specific applications for each client. for example, I'd like to set an amount of bandwidth for youtube videos (ie. 80k) for each client, despite of how many video the user opens simultaneously.

I have 2 interfaces (Internal and Guests) and 2 Wi Fi networks (1 binded to internal, 1 for guest access).

The first question: I'd like to share the Download throttling configuratoin for all interfaces mentioned above, so I tried to create the Download Throttling rules in External interface (that has QoS enabled). But it seems to me that the traffic is never limited. So i create the rules in Internal interface, in this case it seems to work. Do I need to create rules for each interface? Is there any other way to create them in external interface so that the rule is valid for each network?

Second question: how I said I'd like to limit bandwith for youtube for each client. For test purpose I created a Download Throttling rule in Internal interface (that has QoS enabled) setting the limit to 80k, specifiying that the rule is intended "for destination". Then I opened 6-7 videos on the same client: the bandwidth usage that I see in flow monitor for my client's ip is 700-900k. The same occurr if I set SOURCE and SOURCE/DESTINATION. Using SHARED option I obtain values always greater than the 80k limit (ie 400k), but in this case the loading of video frequently stops.

So... where I am wrong?

Any suggestion will be apreciated.

Thanks



This thread was automatically locked due to age.
Parents
  • Daniel, please show us what you have configured in QoS:

    • On the 'Status' tab, Edit the External interface and insert a picture of that.
    • Similarly, show us the Edit of the Traffic Selectors involved here.
    • Bandwidth Pools.
    • Download Throttling rules.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hello,

    these are the screenshots:

     

    I didn't create any bandwidth pool, since I dont want to set a guaranteed bandwidth and the limit should set per user and not globally.

     

    Thanks

  • First, on the Interfaces, leave only 'Uplink Optimizer' checked on "External Navigazione" and uncheck the rest.

    Disable/Delete the "Youtube for Internal" Throttling rule unless your goal is to limit uploads from users in "Internal (Network)."  If that's the case, then you will want a similar rule on the "Guest" interface.  If you don't want to do this, disable QoS for these two interfaces on the 'Status' tab.

    Any luck now?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • No Bob, no luck with these settings.

    Now only Donwload Throttiling for "External Navigazione" is active, limiting to 80 kbit/s for each destination - youtube selector, but my client has 1mbit of bandwidth consumption for youtube application, even if I followed your suggestions for Status tab - "External navigazione".

    In this forum I fouded that QoS is not wokring great with web filltering on, unless you use full transparent mode on web proxy, is it correct?

    Thanks

Reply
  • No Bob, no luck with these settings.

    Now only Donwload Throttiling for "External Navigazione" is active, limiting to 80 kbit/s for each destination - youtube selector, but my client has 1mbit of bandwidth consumption for youtube application, even if I followed your suggestions for Status tab - "External navigazione".

    In this forum I fouded that QoS is not wokring great with web filltering on, unless you use full transparent mode on web proxy, is it correct?

    Thanks

Children
  • "In this forum I fouded that QoS is not wokring great with web filltering on, unless you use full transparent mode on web proxy, is it correct?"

    You should not use Full-Transparent when the UTM is on the edge of your network and it has a public IP on the Interface with a default gateway.  Full-Transparent requires bridged NICs and QoS doesn't work on a bridge.

    If you have a paid license, you will want to get a ticket opened with Sophos Support - someone else needs to put eyes on your configuration.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?