application based traffic shaping has no effect?

Following this article: 

https://community.sophos.com/kb/en-us/123062

Application traffic shaping does not seem to have any effect at all.   

 

I've set a super low bandwidth limit for a policy I call "guest video" (very limited for testing purposes) 

 

 

Applied that policy to a specific application: (in this case I"ve applied it to netflix/youtube/amazon streaming)

 

then applied it to firewall rules:

 

I've tried this on both Captive portal networks and hotspot networks with no effect at all.   missing somthing?

  • You do realise that the limit you have set is 40Kb/s?

    Ian

  • In reply to rfcat_vk:

    Yup, as I mentioned in the post, I have it set super low for testing,  I've also tested it at various intervals from 100Kb/s-1000Kb/s.  I set it super low, to see if it was working because at that speed it should barely load videos.  they still load at full speed.    

  • In reply to Heartwood Hub:

    What does the XG diagnostics show as to speed?

    Is the traffic going through the correct rule, review logviewer.

    Ian

  • In reply to rfcat_vk:

    Log viewer shows traffic going through the correct rule.

    Current live connections show the traffic under the correct application and user. (for the captive portal at least, there is also traffic showing up under application as N/A i'm assuming this is the hotspot user) (for example USER-A watching youtube, live connections show traffic for this user, with MB for youtube streaming) 

    Diagnostics pertaining to speed, is it possible to view speed per user?  I can see WAN speed and interface, but there is other traffic on those ports, so it's difficult to see specifically what each user may be using. 

  • In reply to Heartwood Hub:

    Hi,

    I have been fine-tuning some of my policies and checked them against what you have set.

    There is nowhere in your firewall rule where you are applying your policy, you need to change allow all to your limiting policy.

    Ian

  • In reply to rfcat_vk:

    Changing from "allow all" to an Application policy has no effect.   My understanding is that the filter policy and traffic shaping policy are handled differently.  The Sophos docs on how to set up application-based traffic shaping does not show the necessity to have an application control policy set. 

  • In reply to Heartwood Hub:

    Try following https://community.sophos.com/kb/en-us/132436

    One thing you can test is to block the application and see if that has any effect. It might be that the application is not being detected, if that is the case you should open a support ticket.