博客首页 注册 建议与交流 排行榜 加入友情链接         宝宝相册的专门空间
推荐 投诉 搜索: 帮助

大萝卜的博客

   bu.cublog.cn
关于作者  
姓名:      大萝卜
职业:      听人说,技术支持是IT业最鸡肋的职业,于是我便开始郁闷起来!
个性签名:   我以为我们同属于/30,Ping出Timed out才明白处于不同的Vlan。我尝试着用爱做为Route,并用Traceroute来验证,可是Netstat的Syn_received结果让我无比伤心。于是我选择了deny any和deny ip any any,但是我心里一直期待着Vpn那天的到来,请将我放在你的Acl之内。
Mailto:bxz1981#gmail.com

我的分类  




FortiOS Traffic Shaping and How it Work

Every FortiGate physical interface has its own queues, FortiOS uses three different ones: high, medium, and low priority. The priority value indicates which queue the packet is added to and in what order the packets exit that interface.

Virtual interfaces (for example, VLANs) share the physical interface queues. Virtual interfaces do not have their own queues. All virtual interfaces bound to a particular physical interface will share the same queues of the physical interface.

Inter-VDOM links have a single FIFO (First in, first out) queue (No QoS or traffic shaping).

When the packet is queued it chooses a queue and checks the queue length against the aggregate queue size for the interface, not the length of that particular queue.

There is a single maximum length on the device, but each queue can have up to that many packets.

So, if the queue length is X there can be 3X packets queued, X packets at each of the 3 priorities.

Thus the low priority traffic does not affect the high priority traffic except indirectly on low end units because memory is tight and the more packets that are allocated the more time it takes to find free memory.

How priority is assigned :

  1. All traffic received from a device defaults to the system default. The default is "high" (see tos-based-priority in config system global).
  2. During input processing the priority is re-calculated based on the TOS (Type of Service) bits and the current TOS setting. The default maps all traffic to the high priority. This can be changed using config system tos-based-priority. You can check the default setting using a diagnose command :-

    # diag sys tos-based-priority list
    0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0

    Where 0 means high, 1 means medium and 2 means low. For example, if I change the global default :

    # config system global
    (global)# set tos-based-priority low
    (global)# end

    # diag sys tos-based-priority list
    2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2

  3. If traffic shaping is enabled then the packet priority is set to whatever value is in the shaper configuration. However, if the packet does not push the bandwidth over the guaranteed bandwidth for that shaper then the priority is unconditionally set to high (0).

So, even if you give VoIP traffic a high priority, unless you change the global default then all the FTP traffic will also be high and be on the same queue. As a result the high priority VoIP traffic can get interrupted by the FTP traffic.

You can change the global priority as described above to fix this problem. You can also adjust the TOS based priority if the traffic has different TOS bits assigned for different traffic types. FortiOS traffic shaping acts more like traffic limiting and the guaranteed bandwidth is a best effort.

By adjusting the priorities as described above, it should be possible to shape traffic to meet your requirements.

 发表于: 2007-03-24,修改于: 2007-03-24 15:23 已浏览1703次,有评论0条 推荐 投诉

  网友评论

  发表评论



Copyright © 2001-2006 ChinaUnix.net All Rights Reserved

感谢所有关心和支持过ChinaUnix的朋友们
页面生成时间:0.80076

京ICP证041476号