Hi,
meanwhile I used the Shaper-rules and it is working so far.
I re-checked the Shaper documentation and the provided examples. I re-created my rules (and re-check pipes and queue settings).
Now the setup is as follows:
Pipes (low limits for testing purposes)
Queues
Rules (192.168.9.0/24 is the remote VPN LAN while 192.168.1.0/24, 192.168.30.0/24 are the local ones)
Now I can see the limits working fine on traffic between LAN and Internet, in both directions.
BUT!
Traffic to/ from Wireguard VPN is not limited at all. So I guess the weighting is not taken into account here. Which might interfere with the VOIP traffic beeing capped by a large VPN traffic...
Before going further (and trying to start with the FW rules) I need to know why the Wireguad traffic is not limited? Even when the interface (wireguardGroup) is wrong it should be limited by the default LAN rule, shouldn't it?
Confused,
/KNEBB
meanwhile I used the Shaper-rules and it is working so far.
I re-checked the Shaper documentation and the provided examples. I re-created my rules (and re-check pipes and queue settings).
Now the setup is as follows:
Pipes (low limits for testing purposes)
- Global Upload --> 70Mb/s
- Global Download --> 80MB/s
Queues
- VOIP Upload, weight 80 --> Global Upload Pipe
- VOIP Download, weight 80 --> Global Download Pipe
- LAN Uplaod, weight 15 --> Global Upload Pipe
- LAN Download, weight 15 --> Global Download Pipe
Rules (192.168.9.0/24 is the remote VPN LAN while 192.168.1.0/24, 192.168.30.0/24 are the local ones)
- Seq 3, WireguardGroup, SRC 192.168.9.0/24, DST any, IN --> LAN Download Queue
- Seq 4, WireguardGroup, SRC any, DST 192.168.9.0/24, OUT --> LAN Upload Queue
- Seq 10, WAN, SRC 192.168.30.0/24, DST any, OUT --> VOIP Upload Queue
- Seq 11, WAN, SRC 192.168.1.0/24, DST any, OUT --> LAN Upload Queue
- Seq 20, WAN, SRC any, DST 192.168.30.0/24, IN --> VOIP Download Queue
- Seq 21, WAN, SRC any, DST 192.168.1.0/24, IN --> LAN Download Queue
Now I can see the limits working fine on traffic between LAN and Internet, in both directions.
BUT!
Traffic to/ from Wireguard VPN is not limited at all. So I guess the weighting is not taken into account here. Which might interfere with the VOIP traffic beeing capped by a large VPN traffic...
Before going further (and trying to start with the FW rules) I need to know why the Wireguad traffic is not limited? Even when the interface (wireguardGroup) is wrong it should be limited by the default LAN rule, shouldn't it?
Confused,
/KNEBB
"