[UPDATE 1] My attempt in configuring Application Control Traffic Shaping for Zoom Meetings in Fortigate 201F Firewall

Subject: [UPDATE 1] My attempt in configuring Application Control Traffic Shaping for Zoom Meetings in Fortigate 201F Firewall


Good day from Singapore,


Today 18 June 2021 Friday, our client wanted to prioritise the network traffic for Zoom meetings. They wanted no lag or latency for their Zoom video conferences. I proceeded to configure application control traffic shaping for Zoom meetings in their Fortigate 201F firewall. Fortigate firewall appliances are based on Linux.


These are the reference guides which I have followed:


[1] Configuring application control traffic shaping

Link: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/204835/configuring-application-control-traffic-shaping#Applicat


[2] Application control shaping

Link: https://www.fortinetguru.com/2016/12/application-control-shaping/


[3] Traffic shaping for video calling

Link: https://forum.fortinet.com/tm.aspx?m=130650


[4] Traffic shaping

Link: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/297431/traffic-shaping


Now, login to Fortigate 201F firewall.


Turn on Traffic Shaping

=======================


Go to System > Feature Visibility. Under the section Additional Features, turn on Traffic Shaping.


Create New Traffic Shaper

=========================


Go to Policy & Objects > Traffic Shapers


Click "Create New"


Type: Shared

Name: Zoom Meeting


Under section "Quality of Service":


Traffic priority: High

Bandwidth unit: Mbps

Maximum bandwidth: 300 Mbps

Guaranteed bandwidth: 280 Mbps

DSCP: off


Click OK.


Please note that all the default traffic shapers are shared shapers.


Create New Traffic Shaping Policy

=================================


Go to Policy & Objects > Traffic Shaping Policy


Click "Create New"


Name: Zoom Meeting

Status: Enabled

Comments: leave empty


Under section "If Traffic Matches":


Source: all

Destination: all

Schedule: off

Service: ALL

Application: 

Zoom

Zoom_File.Download

Zoom_File.Upload

Zoom_Login

Zoom_Meeting

URL Category: Leave empty


Under section "Then":


Action: Apply Shaper

Outgoing interface: SD-WAN

Shared shaper: Zoom Meeting

Reverse shaper: Zoom Meeting

Per-IP shaper: off


Click OK.


Create/Edit Internet Access Policy

===================================


Go to Policy & Objects > IPv4 Policy


Click "Create New"


Name: Internet access

Incoming interface: lan

Outgoing interface: SD-WAN

Source: lan network

Destination: all

Schedule: always

Service: ALL

Action: ACCEPT

Inspection Mode: Flow-based


Under section "Firewall / Network Options":


NAT: Enabled

IP Pool Configuration: Use Outgoing Interface Address

Preserve Source Port: off

Protocol Options: PRX, default


Under section "Security Profiles":


AntiVirus: off

Web Filter: off

DNS Filter: off

Application Control: ON (APP, default profile)

SSL Inspection: SSL, certificate-inspection


Click OK.


Tags: QoS, Quality of Service, Traffic Shaping, Traffic Control


===END===


Mr. Turritopsis Dohrnii Teo En Ming, 43 years old as of 19 June 2021, is a TARGETED INDIVIDUAL living in Singapore. He is an IT Consultant with a System Integrator (SI)/computer firm in Singapore. He is an IT enthusiast.





REFERENCES

==========


[1] https://marc.info/?l=lartc&m=162403549713474&w=2

Comments

Popular posts from this blog

[24 Mar 2022 Thursday] Erectile Dysfunction and Viagra

Patching Linux Kernel 5.5.7 to Add Support for AUFS Filesystem