FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Ylli_Seitaj
Staff
Staff
Article Id 371247
Description This article describes how to configure the FortiGate Firewall to prioritize the traffic for Netflix.
Scope FortiGate.
Solution
  1. Go to: 'Application Control' and select 'Create New' to create an Application Control Profile to allow and monitor Netflix applications:

Screenshot_1.png

 

  1. Go to: 'Traffic Shaping' and select 'Create New' to create a Traffic Shaper. Specify: 'Maximum bandwidth' and 'Guaranteed bandwidth'. Below is an example:

    Screenshot_2.png

     

     

  2. Go to: 'Policy & Objects' -> 'Firewall Policy' and select 'Create New' to create a Firewall Policy:

     

    Screenshot_3.png

     

     

As shown in the below link, Netflix does not require deep inspection, so certificate-inspection is enough on the above Firewall Policy:

 

Screenshot_4.png

 

  1. Configure 'traffic-shaper' and 'traffic-shaper-reverse', as explained in below article:
    Traffic Shaping Priority Queueing (PRIQ)


After applying the traffic shaper from CLI, they will be displayed on GUI inside the Firewall Policy:

Screenshot_5.png

 

  1. Use the 'Dashboard' and 'Forward Traffic' logs to monitor Netflix's performance in terms of bandwidth usage and application control.