<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: checkpoint QoS on site to site vpn traffic in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/104009#M4443</link>
    <description>&lt;P&gt;Actually it is possible to differentiate traffic traversing a VPN tunnel in your QoS policy via a checkbox in the Action of a QoS rule like this, which applies this sample rule only to encrypting/decrypting traffic:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="QoS_VPN.png" style="width: 912px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9459iAAE502D4EB53BD4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="QoS_VPN.png" alt="QoS_VPN.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Dec 2020 14:32:59 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2020-12-02T14:32:59Z</dc:date>
    <item>
      <title>checkpoint QoS on site to site vpn traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/103797#M4439</link>
      <description>&lt;P&gt;Hi there is there any way to prioritize the site to site vpn traffic on a checkpoint vpn network? we are doing full mesh vpn for the inter-site voice calls primarily but I would say its more of a hub/spoke topology for the data network where all branch sites connect back to hub site over vpn for data traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any way using QoS to guarantee that these VPN tunnels have a certain amount of bandwidth at all time?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 23:02:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/103797#M4439</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2020-11-30T23:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint QoS on site to site vpn traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/103802#M4440</link>
      <description>&lt;P&gt;You can do QoS on the traffic inside a VPN tunnel (assuming it's a domain-based VPN, route-based VPNs are not supported per &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36157" target="_self"&gt;sk36157&lt;/A&gt;), but I don't believe you can do QoS on the VPN tunnel itself.&lt;BR /&gt;In any case, QoS doesn't make much sense over the public Internet since there is zero guarantee anything there will honor the DSCP tags.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 00:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/103802#M4440</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-01T00:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint QoS on site to site vpn traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/104009#M4443</link>
      <description>&lt;P&gt;Actually it is possible to differentiate traffic traversing a VPN tunnel in your QoS policy via a checkbox in the Action of a QoS rule like this, which applies this sample rule only to encrypting/decrypting traffic:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="QoS_VPN.png" style="width: 912px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9459iAAE502D4EB53BD4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="QoS_VPN.png" alt="QoS_VPN.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 14:32:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/104009#M4443</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-12-02T14:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint QoS on site to site vpn traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/110250#M4861</link>
      <description>&lt;P&gt;i tried to create a similar policy but i receive the following error when i try to install policy on the gateway.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Error - QoS Policy does not apply to any network interface.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me what I missed?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 04:07:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/110250#M4861</guid>
      <dc:creator>nflnetwork29</dc:creator>
      <dc:date>2021-02-09T04:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint QoS on site to site vpn traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/110281#M4862</link>
      <description>&lt;P&gt;I would suggest to follow the QoS Tutorial starting at QoS R80.40 Administration Guide p.32 ! Network Interfaces are the enforcement points for QoS, so QoS has to be enabled on one interface for QoS to be able work on it...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 08:55:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/110281#M4862</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-02-09T08:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint QoS on site to site vpn traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/134102#M6030</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you clarify the situation outlined in SK36157, please? Does it mean QoS is unsupported on Route-based VPNs, or we cannot implement QoS on any interface if a VTI exists on the gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 17:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/134102#M6030</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2021-11-15T17:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint QoS on site to site vpn traffic</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/134114#M6031</link>
      <description>&lt;P&gt;It just can't be done on any traffic to/from VTI interfaces:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34086" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34086&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;It should work on other interfaces.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 21:25:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/checkpoint-QoS-on-site-to-site-vpn-traffic/m-p/134114#M6031</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-15T21:25:41Z</dc:date>
    </item>
  </channel>
</rss>

