This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Download throttling for SSL VPN and WSUS Traffic

Hi there,

i want to throttle the download from our WSUS Server (QoS on the server does not seem to work) to the remote ssl VPN network.

Thanks to 4G when we approve the latest updates our internet line is "full" as 80% of our workers are remote. But not always if so i would set up WSUS Server that does not cache local.

Is there a way to set up download throttling for the remote clients? To which interface can i bound it? The WAN or the internal?

My "rule" is like this.

Traffic from "WSUS server" on these "ports (8530/8531)" to the "Remote subnet". But bound on external it does not seem to work.

Best regards

Stephan



This thread was automatically locked due to age.
Parents
  • If you think about it, your clients are downloading and your server is uploading. Therefore, you will want to limit the upload. For that you will need a bandwidth pool in which you specify the destination as the remote ssl vpn network

  • Hey Louis,

    but they download "from" my server. I don't want to reserve a bandwidth for WSUS because i only need it 2-4 days a month.

    So the pool is the wrong approach.

    Best regards

    Stephan

  • Stephan, if you want to limit downloads from the WSUS server, add a Download Throttling rule on the Internal interface limiting '{WSUS Server} -> Any -> VPN Pool (SSL)'.  If this is a site-to-site VPN instead of Remote Access, replace "VPN Pool (SSL)" with the content of 'Remote Networks' in the SSL Connection.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hey Bob,

    i've set it like you said. How can i check if these rules REALLY apply? Because the WSUS server says that the traffic is higher than the specified value.

    Regards

    Stephan

  • Please show pictures of the Edits of your Traffic Selector and Download Throttling rule.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • There isn't an easy way to check if these rules do apply other than running 3rd party speed tests or watching the bandwidth monitor. It's one thing that the UTM could do with eg pfsense has live bucket graphs etc to show how much QoS is being applied etc.

    One for Bob here:

    As the OP has full control of the network above, a download or an upload rule would work. Which is the preferred way? I know it's recommended to apply QoS etc to the closest interface in general but if the client was say 2 subnets further away, would it be better to apply the upload limiting at the server or the download throttling at the client?

  • In this case, Louis, there's no choice because there's no outbound interface object available on which one could use a Bandwidth Pool that limits uplink traffic.  If the traffic were IPsec instead of SSL VPN, you could do QoS on the External Interface on the outbound IPsec traffic as QoS knows how to look inside an IPsec tunnel.  I'm unaware of any real difference in performance or load on the UTM between limiting inbound traffic with a Download Throttling rule or the corresponding outbound traffic with a Bandwidth Pool that limits uploads, so I try to not use the latter.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Here is the traffic selector:

    And here is the throttling rule (which is not working btw - we had a "full" internet line so i restarted the WSUS server. the bandwidth was cut in half losing 50Mbit traffic) 

    I could also do the other way. Create QoS Bandwith Pools for the important services and let the other "stuff" use the rest.

    Best regards

    Stephan

  • The service is WSUS-port to 1:65000? Otherwise your rule applies in the wrong direction since the clients download from WSUS, WSUS doesn't push the updates. So you have to control the clients traffic to the WSUS and not WSUS-to-client.

    Gruß / Regards,

    Kevin
    Sophos CE/CA (XG+UTM), Gold Partner

Reply
  • The service is WSUS-port to 1:65000? Otherwise your rule applies in the wrong direction since the clients download from WSUS, WSUS doesn't push the updates. So you have to control the clients traffic to the WSUS and not WSUS-to-client.

    Gruß / Regards,

    Kevin
    Sophos CE/CA (XG+UTM), Gold Partner

Children