Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ralph1973
Contributor

traffic shaping in application control

Hello, I have a traffic shaper in an application control profile for an rdp server, that gives low priority to streaming video.

When I select this filter in a firewall policy, I don't configure traffic shaping in the policy as well isn't it?

Then, since it is traffic from outside to inside, it actually needs to be a reversed shaper, but that one cannot be selected in application control profile.

anyone knows how to deal with this?

 

Kind regards,

Ralph Willemsen

2 REPLIES 2
toantrinh_FTNT

Hi Ralph,

 

You are correct, if you configure application traffic shaper, no need to do it at the security policy level...the application shaper takes precedance over the security policy shaper anyway.

 

Are you streaming video separately on different ports? or is the streaming back to the client on the same RDP port?

What version of FortiOS are you running, when configuring Application Traffic Shaper, you have should have two check boxes.

 

 Forward Direction Traffic Shaping  Reverse Direction Traffic Shaping   So if you want reverse, just check the reverse box...   Also, just a suggestion. If the destination service port is static and known, e.g RDP is 3389, you should use the security policy shaper instead of the application shaper to reduce the resource impact on the FortiGate.    
Ralph1973

Hello, thank you for your suggestions. The customer uses FortiOS 5.2.3.

As far as I know, reverse shaper cannot be selected in the Application control section, only in the security policy.

I am wondering how others prevent rdp users on a Terminal server to load e.g. HD video.

We want to prevent users to

- take a lot of (internet) bandwidth by loading big video's or watch streaming media

- take too much resources of the terminal server by watching (hd) movies

 

I was thinking about

- limit bandwidth usage per user by setting traffic shaper on Application security profile. However, then I come to the question that I want to shape it for reverse traffic.

Or should I split the policy and configure a policy above the existing, especially for video traffic, with a reverse shaper in the security policy?

- or is it wise to limit the entire rdp session by a reverse shaper of (e.g.)1Mb ? What is your experience with this?

 

Thank you and have a nice day,

 

Ralph

Labels
Top Kudoed Authors