Netgear SRX5308 SRX5308 Reference Manual - Page 127

Creating Bandwidth Profiles, Apply, Security, Bandwidth Profile

Page 127 highlights

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual 2. Modify the settings that you wish to change (see Table 4-7 on page 4-36). 3. Click Apply to save your changes. The modified QoS profile is displayed in the List of QoS Profiles table. Creating Bandwidth Profiles Bandwidth profiles determine the way in which data is communicated with the hosts. The purpose of bandwidth profiles is to provide a method for allocating and limiting traffic, thus allocating LAN users sufficient bandwidth while preventing them from consuming all the bandwidth on your WAN link. For outbound traffic, you can apply bandwidth profiles on the available WAN interfaces in both the single WAN port mode and auto-rollover mode, and in load balancing mode on the interface that you specify. For inbound traffic, you can apply bandwidth profiles to a LAN interface for all WAN modes. Bandwidth profiles do not apply to the DMZ interface. For example, when a new connection is established by a device, the device locates the firewall rule corresponding to the connection. • If the rule has a bandwidth profile specification, the device creates a bandwidth class in the kernel. • If multiple connections correspond to the same firewall rule, the connections all share the same bandwidth class. An exception occurs for an individual bandwidth profile if the classes are per-source IP address classes. The source IP address is the IP address of the first packet that is transmitted for the connection. So for outbound firewall rules, the source IP address is the LAN-side IP address; for inbound firewall rules, the source IP address is the WAN-side IP address. The class is deleted when all the connections that are using the class expire. After you have created a bandwidth profile, you can assign the bandwidth profile to firewall rules on the following screens: • Add LAN WAN Outbound Services screen (see Figure 4-3 on page 4-13). • Add LAN WAN Inbound Services screen (see Figure 4-4 on page 4-14). To add and enable a bandwidth profile: 1. Select Security > Bandwidth Profile from the menu. The Bandwidth Profiles screen displays (see Figure 4-23 on page 4-38, which shows one profile in the List of Bandwidth Profiles table as an example). Firewall Protection v1.0, April 2010 4-37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual
Firewall Protection
4-37
v1.0, April 2010
2.
Modify the settings that you wish to change (see
Table 4-7 on page 4-36
).
3.
Click
Apply
to save your changes. The modified QoS profile is displayed in the List of QoS
Profiles table.
Creating Bandwidth Profiles
Bandwidth profiles determine the way in which data is communicated with the hosts. The purpose
of bandwidth profiles is to provide a method for allocating and limiting traffic, thus allocating
LAN users sufficient bandwidth while preventing them from consuming all the bandwidth on your
WAN link.
For outbound traffic, you can apply bandwidth profiles on the available WAN interfaces in both
the single WAN port mode and auto-rollover mode, and in load balancing mode on the interface
that you specify. For inbound traffic, you can apply bandwidth profiles to a LAN interface for all
WAN modes. Bandwidth profiles do not apply to the DMZ interface. For example, when a new
connection is established by a device, the device locates the firewall rule corresponding to the
connection.
If the rule has a bandwidth profile specification, the device creates a bandwidth class in the
kernel.
If multiple connections correspond to the same firewall rule, the connections all share the
same bandwidth class.
An exception occurs for an individual bandwidth profile if the classes are per-source IP address
classes. The source IP address is the IP address of the first packet that is transmitted for the
connection. So for outbound firewall rules, the source IP address is the LAN-side IP address; for
inbound firewall rules, the source IP address is the WAN-side IP address. The class is deleted
when all the connections that are using the class expire.
After you have created a bandwidth profile, you can assign the bandwidth profile to firewall rules
on the following screens:
Add LAN WAN Outbound Services screen (see
Figure 4-3 on page 4-13
).
Add LAN WAN Inbound Services screen (see
Figure 4-4 on page 4-14
).
To add and enable a bandwidth profile:
1.
Select
Security
>
Bandwidth Profile
from the menu. The Bandwidth Profiles screen displays
(see
Figure 4-23 on page 4-38
, which shows one profile in the List of Bandwidth Profiles table
as an example).