Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Traffic shaping for VOIP

I setup a FG50A on a remote office IPSEC tunnel to my FG200 at corporate. We have VOIP and want to make sure that it works well through the IPSEC tunnel. I created IPphone service that contains the udp ports used by our phones then created policies. Question 1: Do I only need to create 1 policy (high priority for IPphone service) in the remote office for both remote and corporate ? I read that it should take affect bi-directionally. Question 2: I created a policy for the rest of my traffic as medium priority. Both phone & data policies have max. bandwidth at 1mb on a 1.mb DSL line. Will Fortigate treat this properly. If max traffic is reached on the DSL it will allocate it to the IPphone ? or will it drop start dropping IPphone and regular IP packets.
2 REPLIES 2
Not applicable

I' m about to (hopefully) get a VOIP installation using a " Bizfon" device, and I have some of the same questions. I don' t have it going through a VPN (we have no remote offices yet). Since the system we' re looking at does its own DHCP, NAT, and has some form of SPI for a " firewall" , I was thinking of just putting it on its own subnet. The data provider (Paetek) we were looking at does respect QOS, but I' m a little concerned about the bandwidth we might need reserved for the VOIP traffic (and that would mean that I' d need to run it through our FG100A). My question is, with no need for VPN for VOIP, is it usless redundancy to have the firewall doing traffic shaping when (apparently) our provider would be using QOS to give VOIP traffic priority while traversing their backbone? Or am I missing something?
BBoysza
New Contributor III

Create two different IPSEC policies, using the same tunnel. Create a Service Group and add your custom services to that group. On the first IPSEC policy (we' ll call it the VOIP policy), do your normal source-destination rule, but include the custom service or the service group you created (if you have more than one port to prioritize). Then hit Advanced and turn on traffic shaping. Give the policy a GUARANTEED rate and then make your Maximum rate AT LEAST as much as the guaranteed rate. Set priority to HIGH. On the second Policy, just do you normal source-destination rules here, but leave services to all - for all other traffic. Hit Advanced again and turn on traffic shaping. Set Guaranteed bandwidth to zero, and give it a maximum rate that is sufficient for your purpose but does not hog the entire pipe. Set traffic priority to medium. With this setup, VOIP traffic will match both policies, but use the first one it sees. So set the VOIP policy first in the list. Other IPSEC-bound traffic won' t match those rules and will move on to the next policy. Hope that helps - I have to do this with some firewalls on slower DSL pipes to guarantee service - just not VOIP - same principle, different ports.
Ben McFortiGate - Over 200 deployed. FCNSP Direct FortiNet FTP Link
Ben McFortiGate - Over 200 deployed. FCNSP Direct FortiNet FTP Link
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors