This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Enabling QoS on Guest LAN ?

So,

I've setup a Guest Wifi/Lan, that is directly connected from a separate interface (Called Guest Network), directly to a Wifi AP. NO switch or other item is between the two items.

I can connect to the guest wifi, and I cannot see/ping any internal source item (so my security seems to be setup correctly).  However, I've tried enabling QoS on the Guest LAN, but it doesn't seem to be taking effect.

Here is what I have configured:

Traffic Selector:

Name: Guest Net

Selector Type: Traffic Selector

Source: Guest Network

Service: ANY

Destination: ANY

Download Throttling:

Name: Limit Guest Network

Interface: Guest Network

Position 1

Limit: 512 kbits/s

Limit: Shared

Traffic Selector Any from Guest Network (Network) to Any

Status: 

Guest Network : Enabled

It seems no matter what permutation I try, QoS doesn't seem to get implemented. I'm using Speedtest from my iphone 6 (that is in airport mode with only wifi, so only data from wifi is being used). and it still goes to my max speed.

Any help is appreciated.



This thread was automatically locked due to age.
  • Hi,

    Did you configure Bandwidth Pool in conjunction with Traffic selectors?  Please post some screenshot of the configurations.

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • So I figured this out last night. Forgot to update this thread.

    I had to set my Traffic Selector as ANY < ANY > ANY, then set my bandwidth Pool to my Guest Network, and the Download Limiter to my Guest Network as well.  Once I set that, my downloads seem to be limited. Albeit, the uploads don't seem to be limited (despite me not using a proxy... or at least its in transparent mode).

  • Oliver, we all work better with raw data - that's why Sachin asked that you insert pictures.  I made a suggestion on your other thread about reserving upload bandwidth for your Internal network instead of limiting uploading for your Guest network.  You mention the proxy in Transparent mode.  Please also insert a picture of the 'Global' tab in 'Web Filtering'.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I compiled all of the config windows into a single image (less uploads).

  • Interestingly enough, I did find a bug though...

    If you try to set the upload/download link speed on the status tab, any greater then 9999kbit/s, it generates an error that the number has to be between 1-10000000 (however, anything over 9999, isn't accepted).

  • You can uncheck 'Upload Optimizer' in the Interface on the 'Status' tab.  Do things work as expected after that?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,

    I see QoS configured on the Guest interface which will do the job, you need not require traffic shaping in conjunction with Bandwidth poll restriction here. A traffic selector can be regarded as a QoS definition which describes certain types of network traffic to be handled by QoS.

    As suggested by Bob, uncheck "upload optimizer" and verify the speed.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.