Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
winonawhiley
New Contributor

Slow Facebook down to " dial up speed"

We have a FWF40c (v4.0, build4054,111202 (MR3)) , we don’t have any of the Fortiguard services. All internal IP’s are static and we are not running Active Directory, just simple Windows authentication. There are a few people who are wasting time using Facebook during work hours. We cannot block the Internet, as these folks have to use the Internet to perform their jobs. Furthermore the boss does not want to block FB entirely, he wants to slow it down to dial up speed so people will get frustrated on their own and just stop using it, his thoughts not mine, but he’s the boss. So my mission is come up with a way to do this. Unfortunately I am a newbie in the networking world. Not sure where to start. My understanding is that Application Control only works with a subscription. Therefore, I was thinking of creating an IP Pool of 128.10.0.[201-209] these are the offenders. Create a FW Object for Facebook.com as a FQDN, then create a policy to shape traffic associated with the FW Object. Am I on the right track? Or can my boss’s assignment even be accomplished without subscriptions?
15 REPLIES 15
rwpatterson
Valued Contributor III

ORIGINAL: ede_pfau I know that this will cut my reputation a bit...but I confess I googled for " subnet calculator" and used the first web site that came up to determine the matching subnet mask. Practise over studying, I guess.
I still calculate it in my head, then compare it with the app I have on my PC...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
winonawhiley

Update: ran into issues wasn’t sure if it was me or 40c. I had so many different addresses and policies I just wasn’t sure. So I backed up the working config. Replaced it with an old Linksys for now. Brought the 40c home temp as my firewall at home. I performed an " execute factoryrestore" . Then configured it with FortiExplorer so I couldn’t muck it up. Weird though, after FR and setting it up with FortiExplorer, I still had to add the route 0.0.0.0./0.0.0.0. odd. never had to do that before when doing the inital setup.... Again Firmware Version v4.0,build4054,111202 (MR3). Set up was as follows: Created shared Traffic Shaper “Facebook 5k Shaper” Traffic Priority - low Max bandwidth 5000 Created Application sensor using Application and chose Facebook Monitor Traffic shaping - Facebook 5 K shaper Reverse Direction – Facebook 5 k shaper Packet logging – yes Problem with the settings here. After I configure these settings click OK and then click apply on the main page. I go back and look and the traffic shaper and Reverse traffic shaper revert to the default setting of unchecked with no shapers chosen. Am I doing something wrong that it doesn' t retain the settings??
Dave_Hall
Honored Contributor

Problem with the settings here. After I configure these settings click OK and then click apply on the main page. I go back and look and the traffic shaper and Reverse traffic shaper revert to the default setting of unchecked with no shapers chosen. Am I doing something wrong that it doesn' t retain the settings??
I only personally seen this happen while using an incompatible web browser and/or when I forget to purge/clear the browser cache after a firmware upgrade. Make sure you are editing the correct Application Sensor, too. If you have created a new Application Sensor, the default one will always show up first in the list (e.g. use the pull down tab at the top right side of the page to choose your Application Sensor.) edit: I do see you have added a facebook sensor to " default" in your screenshot, check to see if you haven' t actually created it under another Application Sensor too.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ede_pfau
SuperUser
SuperUser

I don' t think you' re doing anything wrong. The checkboxes indicate that you want to modify the selected item. They are not indicating a status. Besides, you should notice that the AppControl is in effect, or at least apps are logged.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
winonawhiley
New Contributor

Thanks folks, I apologize for not getting back out here sooner, you responded to me right away and I dropped the ball in getting back to you with feedback so we can close the thread as solved. With that said, all is working. Here is what I found out: Browsers matter, IE8 gets stupid sometimes, even with the latest flash BHO’s, so I use chrome with the FGT web interface. App Control works without the bundled services. Reverse traffic shaping is where it is at, we have slowed FB down to a crawl, the boss told his people he did care if FB was slow he wasn’t paying to fix it when they shouldn’t be using it anyway. Also learned that even with slow dial-up speeds after they visit a few times it gets faster because Temporary Internet files cache some of the files. So I set the gals machine to dump files at each and every browser close. That way it has to re-download it all again. That was about the only bump in the road. I do see another bump coming….This office shares their Internet connection and the 40C with another office in the building. Their boss is much more laid back. So the day is coming soon when he tells me to fix it for them. So at that point I am thinking I will have to put each office on their own VLAN? And then apply those setting only to our VLAN. I am hoping that will be the right course of action. Again Thank you for your assistance and direction and patience with me a networking guy in training! Again if you guys can point me to some reading, video and other tutorials for the Fortigates and subnetting in general I would appreciate that, I have so much to learn and no time to do it.
ede_pfau
SuperUser
SuperUser

Glad it' s working now. I have my doubts if throttling FB on your LAN makes sense when at the same time your neighbours are wasting the bandwidth...but that' s politics, not networking. Yes, you could separate the LANs in two VLANs. VLAN interfaces are created as sub-interfaces of a physical port, in your case ' internal' . Your switches will have to support VLANs as well, putting incoming traffic from the PCs onto a VLAN (tagging). I' ve got no idea how big your office is and whether your existing switches are VLAN capable but...I' ve grown very fond of the Netgear Smart Switches like GS108Tv2 for small installations. They even have a web interface, support VLAN tagging and QoS and a lot more at a very decent price. ' Poor man' s VLAN' would work too. Separate the offices by address space, like the lower half of a /24 network for office1 and the upper half for office2. Of course, this will not work if you configure the PCs for DHCP. (you could use DHCP with reserved addresses but that would somehow eliminate the benefits of DHCP). And if only one of your office users is clever enough to put his/her PC onto a different IP address the whole scheme will break down. So, VLANs are the way to go, or better still, seperate WAN lines.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors