Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FatalHalt
Contributor II

Is it possible to Traffic Shape an IPSEC Tunnel?

Hey guys, 

 

I have a case where I'd like to be able to Traffic Shape (Limit maximum bandwidth) traffic that travels over an IPSEC Tunnel. I was trying to see if this was even possible. 

 

In the Traffic Shaping Reference Manual, there's the following paragraph:

VLAN, VDOM and virtual interfaces Policy-based traffic shaping does not use queues directly. It shapes the traffic and if the packet is allowed by the security policy, then a priority is assigned. That priority controls what queue the packet will be put in upon egress. VLANs, VDOMs, aggregate ports and other virtual devices do not have queues and as such, traffic is sent directly to the underlying physical device where it is queued and affected by the physical ports. This is also the case with IPsec connections.

 

Does this mean that I will not be able to shape the IPSec tunnels? Will another method work?

 

Appreciate any insight!

1 REPLY 1
Iescudero
Contributor II

"...VLANs, VDOMs, aggregate ports and other virtual devices ...his is also the case with IPsec connections." this applies just for the priority. "...Limit maximum bandwidth" works and works fine.

Labels
Top Kudoed Authors