synaesthesia Posted March 31, 2017 Posted March 31, 2017 We're starting to have some severe internet usage issues, where our line is being maxed out often. Not so much just by us, but not helped by having a shared Lightspeed Rocket from Schools Broadband. I'd like to look at some sort of QoS on our core as it's clear that something isn't right at SB; one file being downloaded by me shouldn't knock out the internet for the entire school. All documentation on QoS seems to revolve around VOIP. Ideally though, I'd like to be able to say when port X (connected to the internet router) is using 90% of available bandwidth, limit wireless VLANS to (n)Mbps, wired clients to (n)Mbps etc. Is this feasible?
Davit2005 Posted March 31, 2017 Posted March 31, 2017 Alternatively could you do anything on your firewall, maybe a bit easier and if you can base this on IP ranges you could do some easy testing?? We have a Packet Shaper apliance running here but we are a Uni so may be a bit overkill for smaller environments
synaesthesia Posted March 31, 2017 Author Posted March 31, 2017 That's all in @SchoolsBroadband control. I know something isn't right as we've never had this issue before, but we've not heard anything from SB to say otherwise, their first line chap suggested we do something internally. Something's changed, and it's not us!
DMcCoy Posted March 31, 2017 Posted March 31, 2017 I doubt it's going to be any use at the switch level, it's really only going to kick in once the uplinks are contended, it's mostly to make sure realtime apps (like voip) get their packets processed first. It's traffic shaping that you want, and that will be more firewall related, while you can combine QoS with traffic shaping (to make certain apps take priority) it's not easy as there are a couple of methods of tagging packets and not everything agrees. It's likely that you will only be able to affect outgoing traffic too, so downloads are slowed by limiting the ACK responses from received traffic. It it possible with pfsense (I traffic shape at home) but if you value your sanity, you would be better with a more robust appliance, one that uses better, more modern shaping options from linux rather than bsd.
synaesthesia Posted March 31, 2017 Author Posted March 31, 2017 No worries, our mikrotik router was sat at 100% CPU usage. SB rebooted it with a firmware update and it's back down to 25%. All looking good now. Just fiddling around with decent methods of monitoring the whole network. Dude is great, but just not quite enough. HP's IMC software is awesomesauce, absolutely love it. Shame it's ridiculously expensive. Nagios/cacti just not quite there. Looking at Zabbix next.
PotNoodleTech Posted April 3, 2017 Posted April 3, 2017 I sincerely doubt it is your switch - I've never seen "one file download taking out the network" at switch level before even with no QOS defined. Everything should "slow down gently" acrossd the board not just die. I would be fixing my beady eyed stare on your Lightspeed Rocket box.
synaesthesia Posted April 3, 2017 Author Posted April 3, 2017 It already is. I didn't think it was the switch to start with, but with doubts over the capability/capacity of the Lightspeed systems in place at the ISP I was more wondering about taking off some of the strain by doing it in-house. Wasn't going to spend money on it either way.
SchoolsBroadband Posted April 3, 2017 Posted April 3, 2017 We're starting to have some severe internet usage issues, where our line is being maxed out often. Not so much just by us, but not helped by having a shared Lightspeed Rocket from Schools Broadband. I'd like to look at some sort of QoS on our core as it's clear that something isn't right at SB; one file being downloaded by me shouldn't knock out the internet for the entire school. All documentation on QoS seems to revolve around VOIP. Ideally though, I'd like to be able to say when port X (connected to the internet router) is using 90% of available bandwidth, limit wireless VLANS to (n)Mbps, wired clients to (n)Mbps etc. Is this feasible? Hi @synaesthesia, why not use app control on the Fortigate firewall? That should do the trick See http://docs.fortinet.com/uploaded/files/1656/controlling-network-access-using-application-control.pdf Thanks Dave
synaesthesia Posted April 4, 2017 Author Posted April 4, 2017 We have no access to that Dave, the fortigate is managed entirely by you guys and we have no access to it; all we have on site is the capable little Mikrotik router. Your guys seem to think it's filtering related at the moment, things seem OK as it stands but as it's holiday it's difficult to tell.
SchoolsBroadband Posted April 4, 2017 Posted April 4, 2017 Hi again, is this a primary school on a shared VDOM or your own dedicated VDOM? If its for your secondary school then you will have access to this, if a primary it depends on what they purchased. Can you send me over a PM with the case reference and I'll speak with the engineer on the case. Thanks D ave
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now