- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Harmony Mobile 4:
New Version, New Capabilities
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi,
I'm trying to make a simple QoS rule work but not success.
The plan seems to be simple: we have an IPSEC tunnel between our Checkpoint gateway (4600, R80.10) and a third-party.
QoS blade is enabled, and I've just put a couple or rules in place, one with the public IP of the third-party as source, and the other one with the IP as destination. The action is set to limit 30 Mbps as shown below:
For some reason, this is not working, and the bandwidth used by that tunnel spikes up to 60 Mbps
Any help?
Thanks
Um no, when measured in BITS per second you have set an equivalent Limit of 240Mbit in your QoS rules. The uppercase "B" indicates BYTES per second instead of bits. For a 30Mbit limit you either need to change the existing Limit value from 30,000,000 to 3,750,000 or better yet change the QoS units of measure from bytes to bits on this screen of the Global properties to avoid further confusion:
Ouch... 🙈
Just changed, I'll wait a few days to confirm it works and will update the thread.
Many thanks!!!
Hi again,
I thought it was working but yesterday the IPSec tunnel spiked again, as shown in the graphic below, it reached 46.86 Mbps while limited to 30Mbps
Thanks
Based on your QoS rule, connections initiated from the PT_Global_ network are limited to 30Mbps, and connections initiated to the PT_Global_ network from elsewhere are separately limited to 30Mbps. So in theory up to 60Mbps of bandwidth could be consumed at once depending on the direction of connection initiation.
Hi Timothy,
As you see in the bandwidth graphic, it spiked more than 46Mbps only upload (marked in the graphic as Inbound). In the other way (Download/ Outbound in the graphic), there is just a little traffic.
So for some reason, the QoS is not working at all.
Thanks
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY