Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Limiting Bandwidth for ssl vpn connections

Hi Everyone, Has anyone limited the bandwidth that a ssl vpn connection can use? We' re looking to limit the connection speed to 10 MB but I' m not sure how to go about this. Thank you,
4 REPLIES 4
rwpatterson
Valued Contributor III

SSL VPN uses a policy. Just limit that policy.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
ede_pfau
SuperUser
SuperUser

The feature is called ' traffic shaping' . Depending on your FortiOS version you' ll find it in the Firwall menu. Be aware that the figures you enter for the limit are KBytes per second, not Kbits per second. You specify the (named) traffic shaper in the policy. You have a choice of a ' one per policy' limit or a ' one per source IP' limit, depending on your goal. I strongly recommend to have a look at the FortiOS Handbook 4.00MR2, ch. 14, pp. 1693 to get a basic understanding. In v3.00 (only in higher versions) the principle is the same but the menu location might differ.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Not applicable

Thank you for the replies. I read that chapter and think I understand the concept -I only unclear now about which policy to apply the Shaper too - I have several ssl policies - ssl.root to trust where VPN IP pool all, any, accept| ssl.root to Untrust where VPN IP pool all, any, accept, Trust to ssl.root, all, all, any. If I had to guess I' d apply the shaper policy to ssl.root to trust . Am I right? Thanks for any input. Josh
ede_pfau
SuperUser
SuperUser

Well that depends on what you are trying to achieve. ssl.root -> trust controls all sessions that are initiated by SSL VPN clients targeting the internal network. ssl.root -> untrust controls SSL VPN client access to the WAN. Both ways are worth limiting. I' ll have to think about trust -> ssl.root: sessions initiated from your LAN towards SSL VPN clients...is that happening at all? HTH.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors