config firewall shaper per-ip-shaper edit " restrict-traffic" set bps 32 config iplist edit 1 set end <server-ip> set start <server-ip> next end next end config firewall policy edit 123 set src-addr <server-ip> set dst-addr <test-device> set per-ip-shaper " restrict-traffic" next endThe active session is handled by the expected policy id 123. Initially the ip-list was set to the remote ip address; upon reading the cli manual more carefully this has been changed to the server ip address (and existing sessions deleted). In both cases the shaper does not operate as expected. Can anyone suggest what is missing or wrong? What is the best way to achieve our requirement, preferably without creating a policy per remote device?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
set action none set type hour set quota 0and subsequently changed to
set action block set type hour set quota 5A quota of 5MB per hour should be enough for normal data and a firmware download. However neither of the above successfully constrained the bandwidth throughput. I' ll go with " need to update the firmware" but given the overall functionality of the device this will be quite a task.
Mohammad Al-Zard
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.