Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sadhi_Jayz
New Contributor II

Applying Traffic Shaping Profiles with SD-WAN

Hello Fortinet Community,

 

I have configured a traffic shaping profile on my FortiGate firewall, along with a traffic shaping policy where I have assigned a Class ID. However, I am unsure about the correct way to apply the traffic shaping profile to interfaces and set the outbound bandwidth.

In my traffic shaping policy, I have selected the destination interface as the virtual-wan-link (WAN1 + WAN2) as the outgoing interface. My question is: if I apply the traffic shaping profile separately to WAN1 and WAN2, will the traffic shaping function as intended?

 

1.png

 

2.png

 

I would appreciate any clarification or best practices regarding this setup.

Thank you!

4 REPLIES 4
adambomb1219
SuperUser
SuperUser

Why do you want to do this?  Do you actually have a bandwidth problem?

Sadhi_Jayz

Yes, the reason for implementing traffic shaping is to ensure that WAN traffic is prioritized based on business needs. In our case, we need to prioritize traffic for four categories of users:

VIPs – Highest priority

Managers – High priority

Engineers – Medium priority

Juniors – Low priority

adambomb1219

Right but do you actually not have enough bandwidth for your needs?  I don't see many customers implement QoS/shapers at all unless they have a VERY slow and low bandwidth uplink like legacy satellite, DSL, or something else.  In today's world with prolific broadband and high bandwidths shapers are rarely necessary.

Toshi_Esumi
SuperUser
SuperUser

I haven't tested it myself yet. But it should work because traffic shaping/QoS is separate network control components/mechanisms with FGT. If doesn't work as you expect, you should open a ticket at TAC to get it looked at. 


Traffic shapping/QoS is still necessary because not all users can afford multiple symmetric/high bandwidth circuits, like your home, or mixing in satellite and/or LTE because multiple wired network services are not available at the location, or because of some unusual network traffic characteristics, which would impact quality of time sensitive traffic.
Some of our customers even demand it even when they have very highbandwidth circuit(s). And, other SD-WAN vendor's technologies/implementation might include traffic-shaping/QoS as a part of SD-WAN. I know at least one major/popular provider does it. FTNT's/FGT have them separated.

You can't simply dismiss user's requirements when you sell something. Because they might buy those products based on the catalog features. At least most of our customers buy SD-WAN products because they just want SD-WAN, not because they really need SD-WAN, even when they got only one circuit in some cases. If we say "you don't need it", they would go other vendor.

Toshi 

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors