<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint QOS issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241571#M46897</link>
    <description>&lt;P&gt;Looks very promising!&lt;/P&gt;</description>
    <pubDate>Tue, 18 Feb 2025 18:20:02 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-02-18T18:20:02Z</dc:date>
    <item>
      <title>CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241323#M46834</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to confirm whether Check Point can guarantee bandwidth for applications using QoS.&lt;BR /&gt;In SmartDashboard, I can only see "Service" but not "Application" as a selectable option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 05:36:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241323#M46834</guid>
      <dc:creator>Patrickc</dc:creator>
      <dc:date>2025-02-17T05:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241335#M46841</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/119119"&gt;@Patrickc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to the guide:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R80.20/AdminGuides/Locally_Managed/EN/Content/Topics/Working-with-QoS-Policy.htm?tocpath=Appliance%20Configuration%7CManaging%20the%20Access%20Policy%7C_____8" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R80.20/AdminGuides/Locally_Managed/EN/Content/Topics/Working-with-QoS-Policy.htm?tocpath=Appliance%20Configuration%7CManaging%20the%20Access%20Policy%7C_____8&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This refers only services:&lt;/P&gt;
&lt;P class="Procedure_Heading"&gt;&lt;EM&gt;to create a QoS rule:&lt;/EM&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;&lt;EM&gt;Click the arrow next to&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;New&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;&lt;EM&gt;Click one of the available positioning options for the rule:&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;On Top&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;On Bottom&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Above Selected&lt;/SPAN&gt;, or&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Under Selected&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Add Rule window opens. It shows the rule fields in two manners:&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;A rule summary sentence with default values.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;A table with the rule base fields in a table.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;&lt;EM&gt;Click the links in the rule summary or the table cells to select network objects or options that fill out the rule base fields. See the descriptions above.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="Menu_Options"&gt;Note&lt;/SPAN&gt;&amp;nbsp;- You can select for a specified rule to have a specified guarantee and/or limit or be marked as low latency traffic. In case of the latter, there is a single maximum limit percentage for ALL low latency traffic which can be configured globally. See above.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;&lt;EM&gt;To match only for encrypted (VPN) traffic, select&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Match only for encrypted traffic&lt;/SPAN&gt;. The Service column shows "encrypted" if selected.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="5"&gt;
&lt;P&gt;&lt;EM&gt;To limit the rule to a specified time range, select&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Apply only during this time&lt;/SPAN&gt;&amp;nbsp;and select the start and end times. Only connections that begin during this time range are inspected.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="6"&gt;
&lt;P&gt;&lt;EM&gt;DiffServ Mark is a way to mark connections so a third party handles it. To mark packets that are given priority on the public network based on their DSCP, select&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;DiffServ Mark (1-63)&lt;/SPAN&gt;&amp;nbsp;and select a value. To use this option, your ISP or private WAN must support DiffServ. You can get the DSCP value from your ISP or private WAN administrator.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="7"&gt;
&lt;P&gt;&lt;EM&gt;In the&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Write a comment&lt;/SPAN&gt;&amp;nbsp;field, enter optional text that describes the rule. This is shown as a comment below the rule.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="8"&gt;
&lt;P&gt;&lt;EM&gt;Click&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Apply&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="Menu_Options"&gt;Note&lt;/SPAN&gt;&amp;nbsp;- You can drag and drop rules to change the order of rules in the QoS Rule Base&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 08:59:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241335#M46841</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-02-17T08:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241338#M46844</link>
      <description>&lt;P&gt;Hi Akos,&lt;/P&gt;&lt;P&gt;Thnaks your reply,but i want to know&amp;nbsp;How to guarantee bandwidth for an application?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 09:47:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241338#M46844</guid>
      <dc:creator>Patrickc</dc:creator>
      <dc:date>2025-02-17T09:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241339#M46845</link>
      <description>&lt;P&gt;like google meeting or teams&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 09:47:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241339#M46845</guid>
      <dc:creator>Patrickc</dc:creator>
      <dc:date>2025-02-17T09:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241341#M46846</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/119119"&gt;@Patrickc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hm... maybe this is what you are looking for:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Bandwidth-Rate-Limit/td-p/132777" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Bandwidth-Rate-Limit/td-p/132777&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;From @Timothy_Hall:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Limit feature is a function of the APCL/URLF blades which typically inspect traffic to and from the Internet, so you must be matching traffic against an application or site object to use it.&amp;nbsp; Not really applicable for your situation of trying to limit bandwidth consumed by a VPN tunnel, but I suppose you could create some custom application/site objects to match traffic in that tunnel and limit it in an APCL/URLF-capable layer.&amp;nbsp; Here is some more info:&lt;/EM&gt;&lt;/P&gt;
&lt;H2 id="toc-hId-1618789832" class="western"&gt;&lt;EM&gt;Applying APCL/URLF Bandwidth Limits&lt;/EM&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="western"&gt;&lt;EM&gt;One very nice feature of APCL/URLF is the ability to enforce bandwidth limits for undesirable sites/applications that cannot be flat-out blocked due to political reasons. A classic example is Media Streaming sites than can consume very large amounts of bandwidth but are not directly required for typical business functions:&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkosBakos_0-1739786334814.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29626i16C4897303F95884/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AkosBakos_0-1739786334814.png" alt="AkosBakos_0-1739786334814.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="western"&gt;&lt;EM&gt;Bandwidth limits for APCL/URLF&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT size="4"&gt;are applied directly by these&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;features, and the full-fledged Quality of Service (QoS) feature does not need to be enabled by the firewall to use them.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western"&gt;&lt;EM&gt;Bandwidth guarantees cannot be specified; the full QoS blade is required for that functionality.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western"&gt;&lt;EM&gt;Upload bandwidth limits, download bandwidth limits, or both can be specified.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western"&gt;&lt;EM&gt;Note that any bandwidth limit enforced will be shared by all connections matching that particular rule; the limits are not per-connection or per-user. It is also not currently possible to enforce overall bandwidth limits over a certain timeframe (i.e. allow 1GByte of streaming data per 24-hour period and then no more until the next day when another 1GByte is allowed).&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western"&gt;&lt;EM&gt;Packets in excess of the configured bandwidth limit are simply dropped by the firewall (this forcing TCP to slow its send rate); these packets are not queued or shaped by the firewall.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;The QoS blade is probably more appropriate for what you are trying to do, and it is very easy to tag/match VPN traffic specifically when enforcing a QoS limit or guarantee by checking the&amp;nbsp;&lt;STRONG class="menuoptions"&gt;Apply rule only to encrypted traffic&amp;nbsp;&lt;/STRONG&gt;checkbox in the QoS rule specifying the limit.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 13:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241341#M46846</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-02-17T13:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241447#M46885</link>
      <description>&lt;P&gt;The QoS blade does not currently support Applications.&lt;BR /&gt;However, you should look at &lt;A href="https://www.checkpoint.com/quantum/sd-wan/" target="_self"&gt;Quantum SD-WAN&lt;/A&gt;, which should be able to do this and more.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 23:45:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241447#M46885</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-17T23:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241459#M46888</link>
      <description>&lt;P&gt;Yep, thats perfect option.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 00:35:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241459#M46888</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-18T00:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241569#M46896</link>
      <description>&lt;P&gt;This is the best, on CPX I got a live demo and it looks wayyy better then traditional QoS blade.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SD-WAN is the new QoS and ISP redundancy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 17:54:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241569#M46896</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-18T17:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint QOS issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241571#M46897</link>
      <description>&lt;P&gt;Looks very promising!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 18:20:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-QOS-issue/m-p/241571#M46897</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-18T18:20:02Z</dc:date>
    </item>
  </channel>
</rss>

