CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > QoS (Quality of Service) (Formerly FloodGate-1)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-23
Jay_D Jay_D is offline
Junior Member
 
Join Date: 2007-07-02
Posts: 14
Rep Power: 0
Jay_D has an average reputation (10+)
Default QoS rules direction

Hi,

this probably sounds like a noob-question, but I am doubting:
I want to limit Outlook RPC over HTTPS (Outlook Anywhere) communication. This traffic goes from somewhere on the internet to a DMZ server. This DMZ server then sends the traffic to the client on the internet.
The security rule for this is
any to DMZ-server for service https allow.
Of course this rule allows the return traffic to go to the client.
Is the same true for QoS rules?
Is a rule from any to DMZ-server for service https limit 512 kbit enough? Or should I also create a rule from DMZ-server to WAN limit 512 kbit?

I got doubts and want to be certain....the bulk of the traffic is sent as a reply to a connection initiated from the internet so I assume a QoS rule just like the security rule is sufficient?

TIA,
JD.
Reply With Quote
  #2 (permalink)  
Old 2008-04-27
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: QoS rules direction

I'm no Floodgate expert but I've always been under the impression you would write the rules in the same direction as the firewall rules, so:

any -> DMV-server https limit 521
Reply With Quote
  #3 (permalink)  
Old 2008-04-28
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 355
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: QoS rules direction

Yeah, that rule should do the trick.

I don't usually recommend using limits though. If you use just the priorities you will make the best possible use of available bandwidth, so I don't really see a reason to limit stuff.
Reply With Quote
  #4 (permalink)  
Old 2008-05-20
Jay_D Jay_D is offline
Junior Member
 
Join Date: 2007-07-02
Posts: 14
Rep Power: 0
Jay_D has an average reputation (10+)
Default Re: QoS rules direction

Thanks all for your reply.

I sometimes prefer limits because this always works. If you have http and smtp going at the same time, then Floodgate doesn't seem to give more bandwidth to http. It's as if some time has is needed to lower the bandwidth for smtp but by the time that's done, the http requests is no longer needed.
Maybe weights are good for traffic that take some time like a download/upload more for those spikes like normal browsing, I don't think it works very well.

I always limit smtp as this eats bandwidth and nobody cares if a mail arrives in 1 second or 10 minutes, as long as it arrives.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:27.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0