use traffic shaper in firewall rule

Started by _shorty, June 24, 2025, 04:10:38 PM

Previous topic - Next topic
Hi there,

I do have currently a running setup with a traffic shaper to limit uploading traffic from my nas to the offsite location. This traffic shaper is currently manually enabled or disabled depending on my working hours from home office.
I would like to automate it and use this traffic shaper in a firewall rule. Because this offsite location connects via Wireguard I tested rules in the LAN and WG0 Network part of the rules but nothing worked so far.

How can I achive this because only adding the queue or rule won't change (or better limit) anything. Is there a trick that I need to know to get it working?

Regards,
Shorty

Its a rule so for it to work it needs to be 1st matched.

If you put it into pf (firewall rules), it needs to be on the TOP, if any other rule before it is being matched the rule with shaper attribute will not be applied.

Regards,
S.
Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD

July 09, 2025, 08:32:07 AM #2 Last Edit: July 10, 2025, 02:10:45 PM by _shorty Reason: adding more information
Thanks @Seimus , but do I need to assign Pipes or Queues to the rule and how should this rule look like?
I created one on LAN network with destination WG0 but it isn't applying this rule (attachments).




Yes you need to put in there either an already configured Pipe or a Queue that is attached to a Pipe.

the Rule direction is IN which I think means Upload reverse should be download.

Did you try to switch it?

Regards,
S.
Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD