Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Guaranteed Bandwidth of IPSEC tunnel.

Hi,
I am quite new to Sophos and would need some help on QoS . We have Site-to-site IPSec VPN configured to our remote branch. WAN speed (in/out) in the main office - 20 Mbit/sec . WAN speed (in/out) in the branch - 10Mbit/sec
Is it possible to assign 10 Mbits of guaranteed Bandwidth to this tunnel
(Branch -> Main 10 mbit/sec, Main -> Branch 10 mbit/sec) ?
How can I do that step-by-step ?

p.s. Sorry for my English, if I do something wrong I wrote.



This thread was automatically locked due to age.
Parents
  • Hi, Alex, and welcome to the UTM Community!

    You can guarantee  10mbps  to the outbound traffic, but the only way you can guarantee the same to inbound traffic is to restrict all other traffic to  10mbps.  Is that what you want to do?

    Cheers - Bob

  • A bit different...

    Branch office channel bandwidth is 10 mbit

    Main office channel bandwidth is 20 mbit

    Guaranteed bandwidth of IPSEC  (branch) is 10 mbit

    For example Ipsec channel uses 8 Mb  of  main office channel bandwidth (ipsec channel is not fully loaded). Main office channel  should use the remaining 12 Mbps.

    If ipsec channel required full guaranteed bandwidth (10 mbit), then the main office traffic will be restricted to 10 mbit. 

    I do not want to strictly limit the traffic to services.

    Is it possible ? 

  • The problem is that a single Internet download can use up all 20mbps of your inbound bandwidth. Your UTM can determine what it sends outbound into your WAN connection, but it has no way of controlling what fills that pipe from the Internet.

    Only your ISP can guarantee 10mbps of inbound bandwidth to IPsec traffic from your remote site if you don't want to limit all other traffic to 10mbps.

    Cheers - Bob

  • Can i create 2 or more pipes in UTM ?
    1st pipe - IPSEC (priority 6, bandwidth 10mbit)
    2nd pipe - All traffic
    First traffic will pass through the first IPSEC pipe with precedence 6 and bandwidth 10 mbit, then traffic will be directed to a common channel with fixed perecedence 6.
    The UTM determines that traffic to come from IPSEC pipe and determine the channel loading.
    If the download does not complete the channel, then rest of the channel width will be used by other traffic
    This technology is used in dlink routers, from which i want to transfer settings to Sophos.

    I plan to set up a second Ipsec channel to 2-nd branch.
    If the channel is set up, it will be necessary to increase the width
    channel head office at 10 Mbps
    Besides two channels ipsec there are other services that need access to the main office
    (RDP, mail and other )

    Maybe it makes sense to configure ipsec traffic with higher priority than other traffic ?

    And not to use the guaranteed bandwidth ?

Reply
  • Can i create 2 or more pipes in UTM ?
    1st pipe - IPSEC (priority 6, bandwidth 10mbit)
    2nd pipe - All traffic
    First traffic will pass through the first IPSEC pipe with precedence 6 and bandwidth 10 mbit, then traffic will be directed to a common channel with fixed perecedence 6.
    The UTM determines that traffic to come from IPSEC pipe and determine the channel loading.
    If the download does not complete the channel, then rest of the channel width will be used by other traffic
    This technology is used in dlink routers, from which i want to transfer settings to Sophos.

    I plan to set up a second Ipsec channel to 2-nd branch.
    If the channel is set up, it will be necessary to increase the width
    channel head office at 10 Mbps
    Besides two channels ipsec there are other services that need access to the main office
    (RDP, mail and other )

    Maybe it makes sense to configure ipsec traffic with higher priority than other traffic ?

    And not to use the guaranteed bandwidth ?

Children