It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda CloudGen Firewall

This Firmware Version Is End-Of-Support

Documentation for this product is no longer updated. Please see End-of-Support for CloudGen Firewall Firmware for further information on our EoS policy.

How to Create and Apply QoS Bands

  • Last updated on

To connect traffic shaping settings with the forwarding firewall ruleset, you must apply an existing or new QoS band. To configure a new QoS band, proceed as follows:

Step 1. Create a QoS Band

To create a new QoS band, complete the following steps:

  1. Go to CONFIGURATION > Configuration Tree > Box > Traffic Shaping.
  2. Click Lock.
  3. Click the QoS Band tab. 
  4. Right-click the QoS Band table and select Add new QoS Band.
  5. In the Name field, enter a descriptive name. (The ID field specifies the index number of the new QoS band.)
  6. Click OK.
  7. In the QoS Band Rule window, you can edit the following settings to specify the priority, interface, and conditions for traffic that is handled by the QoS band:

    SettingDescription
    Priority

    From this list, select the priority class that is assigned to data packets that are handled by the QoS band.

    Virtual DeviceFrom this list, select the virtual interface into which the data packets will be fed, should this rule apply.
    TOSTo specify a value that must be matched by the TOS in the IP header, select this check box.
    Traffic LimitTo specify a data limit that must not be exceeded by network sessions, select this check box.
    Time PeriodTo specify specific dates and times during which this rule can be applied, select this check box.
    Weekday/HourTo specify specific weekdays and times during which this rule can be applied, select this check box.
  8. Click OK.
  9. Click Send Changes and Activate.

Example Scenario

 qos_scheme01.png

Step 2. Apply the QoS Band to a Firewall Rule

To apply traffic shaping to an access or application rule, complete the following steps:

  1. Go to CONFIGURATION > Configuration Tree > Box > Assigned Services > Firewall > Forwarding Rules.
  1. Click Lock.
  2. Create or double-click the access or application rule to which you are applying the QoS band. For example, LAN-2-INTERNET-https.
    • To apply the QoS band to an access rule:
      • Select the QoS band from the QoS Band (Fwd) and QoS Band (Reply) list in the Policy section. For example, Background.

        The outbound and inbound rate of a virtual interface is ignored when the QoS Band policy in the corresponding firewall rule is set to No-Shaping.

    • To apply the QoS band to an application rule:
      • Select the Change QoS Band (Fwd) check box in the Policy section and select the QoS band from the list.

  3. Click OK.
  4. Click Send Changes and Activate.

You can also apply traffic shaping settings to multiple rules. In the rule editor window for the rules, specify the following settings:

  • In the Rule Settings section, configure the Forward Band and Reverse Band settings.
  • In the TCP Policy section, configure the Syn Flood Protection setting.

For more information, see  How to Edit, Copy, Clone, Deactivate, or Delete Access Rules.

Applying Traffic Shaping to VPN Tunnels

You can implement traffic shaping with VPN. For more information, see  How to Apply Traffic Shaping to a VPN Tunnel.