Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MarcusLeung
New Contributor

Traffic shaping profiles, diagnose netlink interface list show Qdisc=noqueue

Hi team,

 

I am currently testing Traffic Shaping Profile in v7.2.8 FortiGate 601F with NP7 (default-qos-type: policing, as shaping is not recommended).

NP7 traffic shaping | FortiGate / FortiOS 7.2.8 | Fortinet Document Library

 

I find the netlink interface shows "Qdisc=noqueue" and the guaranteed bandwidth in profile is not working. I set one to 99% and other 1%, but iperf test has no difference, they share 50-50% traffic.

But the maximum bandwidth in profile is working, if I set 5%, the iperf result shows down to 5Mbps immediately.

 

From the admin guide, I see the log is Qdisc=pfifo_fast.
Traffic shaping profiles | FortiGate / FortiOS 7.2.8 | Fortinet Document Library

 

Any idea to config FortiGate to use Qdisc=pfifo_fast, so that to further test the Traffic shaping profiles?

 

Netlink:

FortiGate-601F # diagnose netlink interface list <VPN interface>

if=<VPN interface> family=00 type=768 index=289 mtu=1420 link=0 master=0
flags=up p2p run noarp multicast
Qdisc=noqueue
egress traffic control:
bandwidth=100000(kbps) lock_hit=18 default_class=2 n_active_class=2
class-id=3 allocated-bandwidth=99000(kbps) guaranteed-bandwidth=99000(kbps)
max-bandwidth=100000(kbps) current-bandwidth=0(kbps)
priority=low forwarded_bytes=0
dropped_packets=0 dropped_bytes=0
class-id=2 allocated-bandwidth=1000(kbps) guaranteed-bandwidth=1000(kbps)
max-bandwidth=100000(kbps) current-bandwidth=0(kbps)
priority=top forwarded_bytes=120
dropped_packets=0 dropped_bytes=0
stat: rxp=34381725 txp=94045094 rxb=5947262736 txb=126799962736 rxe=0 txe=273 rxd=0 txd=0 mc=0 collision=0 @ time=1728370526
re: rxl=0 rxo=0 rxc=0 rxf=0 rxfi=0 rxm=0
te: txa=0 txc=0 txfi=0 txh=0 txw=0
misc rxc=0 txc=0
 
Below is the other config of the QoS:
 

config system interface
edit 
<VPN interface>

set vdom "root"
set ip x.x.x.x 255.255.255.255
set type tunnel
set outbandwidth 100000
set egress-shaping-profile "Profile-2"
set remote-ip x.x.x.x 255.255.255.255
set snmp-index xxx
set interface "xxx"
next
end

 

config firewall shaping-profile
edit "Profile-2"
set default-class-id 2
config shaping-entries
edit 2
set class-id 2
set priority low
set guaranteed-bandwidth-percentage 1
set maximum-bandwidth-percentage 100
next
edit 3
set class-id 3
set priority top
set guaranteed-bandwidth-percentage 99
set maximum-bandwidth-percentage 100
next
end
next
end

 

Thanks!

Marcus

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors