Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - via

#1
Cheers for that, was totally unaware. Never touched shaping before so went with fq_codel as that was what tutorial used lol

Will have a dig in further and try a different queue type. Can you mix and match? E.g. leaving fq_codel for normal traffic and setup different pipe and queues for VOIP? As there is a difference since using this for bufferbloat.

VOIP is very low bandwidth anyway and on 900 up/down but just want to make sure it is prioritised over everything else as that is my business phone line so want to make sure it runs as good as it can, nothing more off-putting than a bad quality line when trying to speak to a customer.

Otherwise happy for the rest to fight for the remaining bandwidth (well for now at least, may tweak it some more in future).
#2
My stupidity... missed sequence option - changed those so high priority first and appears to be working as expected now.
#3
I've used the guide at https://maltechx.de/en/2021/03/opnsense-setup-traffic-shaping-and-reduce-bufferbloat/ as starting point with modification of weight for queues set at 50.

I've then duplicated these queues for "high priority" with a weight of 100 and created two additional rules for VOIP base (pic attached).

However status shows everything still using normal download queue. (pic attached)

I am guessing I've done something incorrect in rules but only addition I've added was VOIP IPs in Source/Destination which in my head are right way round for Upload/Download.

Can anyone offer any pointers?
#4
General Discussion / VLAN rules
November 19, 2019, 05:05:45 PM
I am trying to configure a VLAN which will be home to my various devices (plugs,lights,etc...) I have setup a VLAN interface (and DHCP) on opnsense and a seperate wireless network on unifi access point.

My current LAN uses 10.0.0.0/20 and new vlan uses 192.168.1.0/24 presently I have just added a pass all rule to try and get it working. So far it kind of works....

Connecting to new SSID gives me an ip in correct range (192.168.1.100) from this I can access internet OK and ping anything on existing 10.0.0.0/20 network (which will be blocked later on) but from any device on normal lan I cannot ping 192.168.1.100.

I can ping the opnsense interface ip OK (192.168.1.1) but not the device. I can happily ping this from router so ICMP is not disabled on device.

Firewall rules are simple default allow rule on lan and a blanket allow for the new vlan.

What am I missing to allow communication from Lan to Vlan?