Define QoS rules in QoS Policy elements
After creating a QoS Policy, add QoS rules to it.
- The order of the rules in a QoS Policy does not affect how the NGFW Engine handles traffic, as the match is made based on the QoS Class.
- If you want to use the same QoS Policy on interfaces that have different types of throughput and use the Full QoS Mode, enter Guarantees and Limits as percentages.
- If you want to use the QoS Policy on interfaces that use DSCP Handling and Throttling QoS Mode, enter Guarantees and Limits in kilobits per second.
- Operations are made according to the matching rule in the QoS Policy that is assigned to the interface that the traffic uses to exit the NGFW Engine.
- The rules do not need to cover all traffic. When Full QoS is used, traffic that is not covered is given a priority of 8 without limits or guarantees.
For more details about the product and how to configure features, click Help or press F1.
Steps
QoS Policy Editing view
Use this view to edit a QoS Policy element.
Option | Definition |
---|---|
Resources | Use this pane to create and add elements to the policy. |
Search | Opens a search field for the selected element list. |
Up (Backspace) | Navigates up one level in the navigation hierarchy. Not available at the top level of the navigation hierarchy. |
New | Opens the associated dialog box to create an element. |
Tools | Show Deleted Elements — Shows elements that have been moved to the Trash. |
Option | Definition |
---|---|
Policy Toolbar | |
Save | Saves the changes. |
Undo operation | Undoes the last change made. |
Redo operation | Redoes the last change that was undone. |
Tools | |
Expand Rule Sections | If you have added Rule Sections, they are expanded. |
Collapse Rule Sections | If you have added Rule Sections, and they are expanded, they are all collapsed. |
Option | Definition |
---|---|
QoS tab | |
ID |
An identifier that shows the order of the rules. The number changes as you add, remove, and move rules. Right-clicking this type of cell opens these menu items:
|
QoS Class |
A list of the defined QoS Classes, which match the QoS rules to traffic. The QoS Class is assigned to traffic in Access rules or through the DSCP Match cell in the QoS Policy. Right-clicking this type of cell opens these menu items:
|
Guarantee |
Sets the minimum bandwidth given to this type of traffic under any conditions. The guarantee can be set in kilobits per second or as a percentage of the available bandwidth.
|
Limit |
Sets the maximum bandwidth that this type of traffic is allowed to consume at any single moment as kilobits per second or as a percentage of the available bandwidth.
|
Priority | Assigns this type of traffic a number that determines the order in which the NGFW Engine sends packets onwards if there is not enough bandwidth available to send all packets onwards directly, so that packets have to be queued. The priority is a number between 1 (highest priority) and 16 (lowest priority). Higher-priority packets are inserted in the queue ahead of any lower-priority packets already in the queue.
|
Weight |
The weight of the QoS Class controls the distribution of bandwidth between QoS Classes with the same priority after the Guarantees for the QoS Classes are reached. The weight of the QoS Class is entered as a value from 0 to 100. The relative weight of each QoS Class is displayed in parentheses as a percentage.
|
Latency |
The average time packets are held in the queue for Active Queue Management (AQM). The NGFW Engine makes a best effort to handle the packets within the specified time, but the Latency value is not a guarantee.
|
Comment |
An optional free-form comment for your own reference. Right-clicking this type of cell opens these menu items:
|
Rule Name |
Contains a rule tag and optionally a rule name.
Right-clicking this type of cell opens these menu items:
|
Option | Definition |
---|---|
DSCP Match/Mark tab | |
ID |
An identifier that shows the order of the rules. The number changes as you add, remove, and move rules. Right-clickingthis type of cell opens these menu items:
|
QoS Class |
A list of the defined QoS Classes, which match the QoS rules to traffic. The QoS Class is assigned to traffic in Access rules or through the DSCP Match cell. Right-clicking this type of cell opens these menu items:
|
DSCP Match |
Assigns the rule’s QoS Class to traffic when the DSCP code (ToS field) defined in this cell is seen in traffic. The value specified in this cell is the only option that is applied on the interface that the packets use to enter the NGFW Engine. Right-clicking this type of cell opens these menu items:
|
DSCP Mark |
Defines the DSCP code (ToS field) that is written to packets that match this DSCP Match/Mark rule when the packets exit the NGFW Engine. The DSCP Mark allows you to communicate the priority of this traffic to other devices that support QoS. You can also use the cell to clear the DSCP classification set by other devices by entering 0 as the value (shown in the policy as 0x00). Right-clicking this type of cell opens these menu items:
|
Comment |
An optional comment for your own reference. Right-clicking this type of cell opens these menu items:
|
Rule Name |
Contains a rule tag and optionally a rule name.
Right-clicking on this type of cell opens these menu items:
|
Option | Definition |
---|---|
General tab | |
Name | The name of the rule. |
Rule Tag | The rule's tag. |
Comment | An optional comment for your own reference. |
Rule Info tab | The rule cells and their values. |
History |
|