Reverse direction traffic shaping

Reverse direction traffic shaping

The shaper you select in the traffic shaping policy (shared shaper) will affect the traffic in the direction defined in the policy. For example, if the source port is lan and the destination is wan1, the shaping affects the flow in this direction only — affecting the upload speed of the outbound traffic. By selecting Shared Traffic Shaper Reverse Direction, you can define the traffic shaper for the policy in the opposite direction to affect the download speed of the inbound traffic. In this example, from wan 1 to lan.

 

To add a reverse shaper

  1. 1. Go to Policy & Objects > Traffic Shaping Policy.
  2. 2. Click Create New or select an existing policy and click Edit.
  3. 3. Set the Matching Criteria to match the interfaces of any security policies you wish to affect.
  4. 4. Navigate to the Apply shaper section, enable the Shared Shaper, and select a shaper from the dropdown menu.
  5. 5. Enable the Reverse Shaper and select a shaper from the dropdown menu.
  6. 6. Select OK.

 

Setting the reverse direction only

There may be instances where you only need traffic shaping for incoming connections, which is in the “reverse” direction of typical traffic shapers.

 

To add a reverse shaper – web-based manager:

1. Go to Policy & Objects > Traffic Shaping Policy.

2. Click Create New or select an existing policy and click Edit.

3. Set the Matching Criteria to match the interfaces of any security policies you wish to affect.

4. Navigate to the Apply shaper section, enable the Reverse Shaper and select a shaper from the dropdown menu.

5. Select OK.

 

To configure a reverse-only shaper in a traffic shaping policy – CLI:

config firewall shaping-policy edit <policy_number>

set reverse-traffic-shaper medium-priority end

 

To configure a reverse-only shaper within a security policy- CLI:

config firewall policy edit <policy_number>

set traffic-shaper-reverse <shaper_name>

end


Having trouble configuring your Fortinet hardware or have some questions you need answered? Ask your questions in the comments below!!! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

Leave a Reply

Name *
Email *
Website