- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hi,
I'm trying to make a simple QoS rule work but not success.
The plan seems to be simple: we have an IPSEC tunnel between our Checkpoint gateway (4600, R80.10) and a third-party.
QoS blade is enabled, and I've just put a couple or rules in place, one with the public IP of the third-party as source, and the other one with the IP as destination. The action is set to limit 30 Mbps as shown below:
For some reason, this is not working, and the bandwidth used by that tunnel spikes up to 60 Mbps
Any help?
Thanks
Um no, when measured in BITS per second you have set an equivalent Limit of 240Mbit in your QoS rules. The uppercase "B" indicates BYTES per second instead of bits. For a 30Mbit limit you either need to change the existing Limit value from 30,000,000 to 3,750,000 or better yet change the QoS units of measure from bytes to bits on this screen of the Global properties to avoid further confusion:
Ouch... 🙈
Just changed, I'll wait a few days to confirm it works and will update the thread.
Many thanks!!!
Hi again,
I thought it was working but yesterday the IPSec tunnel spiked again, as shown in the graphic below, it reached 46.86 Mbps while limited to 30Mbps
Thanks
Based on your QoS rule, connections initiated from the PT_Global_ network are limited to 30Mbps, and connections initiated to the PT_Global_ network from elsewhere are separately limited to 30Mbps. So in theory up to 60Mbps of bandwidth could be consumed at once depending on the direction of connection initiation.
Hi Timothy,
As you see in the bandwidth graphic, it spiked more than 46Mbps only upload (marked in the graphic as Inbound). In the other way (Download/ Outbound in the graphic), there is just a little traffic.
So for some reason, the QoS is not working at all.
Thanks
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY