Traffic Shaping
Guaranteed bandwidth and maximum bandwidth
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
423
•
Traffic Shaping
Traffic shaping, once included in a firewall policy, controls the bandwidth available to, and
sets the priority of the traffic processed by, the policy. Traffic shaping makes it possible to
control which policies have the highest priority when large amounts of data are moving
through the FortiGate unit. For example, the policy for the corporate web server might be
given higher priority than the policies for most employees’ computers. An employee who
needs extra high speed Internet access could have a special outgoing policy set up with
higher bandwidth.
Traffic shaping is available for firewall policies whose Action is ACCEPT, IPSEC, or SSL-
VPN. It is also available for all supported services, including H.323, TCP, UDP, ICMP, and
ESP.
Guaranteed and maximum bandwidth in combination with queuing ensures minimum and
maximum bandwidth is available for traffic.
Traffic shaping cannot increase the total amount of bandwidth available, but you can use it
to improve the quality of bandwidth-intensive and sensitive traffic.
For more information about firewall policy, see
This section describes:
•
Guaranteed bandwidth and maximum bandwidth
•
•
Traffic shaping considerations
•
Guaranteed bandwidth and maximum bandwidth
When you enter a value in the
Guaranteed Bandwidth
field when adding a traffic shaper,
you guarantee the amount of bandwidth available for selected network traffic (in
Kbytes/sec). For example, you may want to give a higher guaranteed bandwidth to your e-
commerce traffic.
When you enter a value in the
Maximum Bandwidth
field when adding a traffic shaper, you
limit the amount of bandwidth available for selected network traffic (in Kbytes/sec). For
example, you may want to limit the bandwidth of IM traffic usage, to save some bandwidth
for the more important e-commerce traffic.
The bandwidth available for traffic set in a traffic shaper is used for both the control and
data sessions and for traffic in both directions. For example, if guaranteed bandwidth is
applied to an internal and an external FTP policy, and a user on an internal network uses
FTP to put and get files, both the put and get sessions share the bandwidth available to
the traffic controlled by the policy.
Once included in a firewall policy, the guaranteed and maximum bandwidth is the total
bandwidth available to all traffic controlled by the policy. If multiple users start multiple
communications session using the same policy, all of these communications sessions
must share from the bandwidth available for the policy.
Note:
For more information about traffic shaping you can also see the
.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...