?
Solved

Implementing QoS without QoS-capable switches on remote site (Juniper SSG)

Posted on 2013-06-19
3
Medium Priority
?
633 Views
Last Modified: 2013-06-24
Dear experts,

I have a situation where we have a main site (data center) and several remote sites (hub sites).


All sites have Juniper SSG firewall (5,20,140,520) with site-to-site VPN tunnels in between the DC and the remote sites.

In the data center all hardware server, OS, switches and firewall is fully QoS capable.
In the remote sites, some have low-cost netgear switches which have no or only basic QoS functionality.

I have the need to prioritize traffic since we are migrating to a VMWare Mirage platform for the clients while also we need to guarantee traffic for Oracle and client access gets priority over web/mail traffic.

My question basically is which of the below approaches is required or even an alternative please ?

Thanks in advance !

1) I need to implement QoS everywhere: Client -> switch -> firewall -> VPN -> firewall -> switch -> server
2) I need to implement QoS everywhere except the client: switch -> firewall -> VPN -> firewall -> switch
3) I can implement QoS only between the firewall (based on policy/port traffic) and the queue will be handled by the firewall's
0
Comment
Question by:ulensr
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 12

Accepted Solution

by:
ryan80 earned 750 total points
ID: 39260168
First off, unless you have a private line/ MPLS there will be no QOS over the internet. once you hit the ISP there will be no qos.

now within your network you can implement qos as needed.  If you feel that there will be contention on the switch you can replace it with something that can handle qos. it really depends on how much traffic you have and how the switch handles it. However I would imagine that the bottle neck is going to be WAN connection not the switch, so I would treat that as secondary.

I have not worked with Junipers before but a quick search shows it to be fairly straight forward. http://www.howtonetworking.com/Routers/ssg4.htm
http://hydra.ck.polsl.pl/~helot/ipad/DayOne-Book/DO_Deploying_Basic_QoS.pdf

You should be able to set the priority of the traffic higher or give it a specific amount of bandwidth.
0
 

Author Closing Comment

by:ulensr
ID: 39270472
Thanks for your answer; although this doesn't completely solve my issue, your advice shows that technically there we do not meet the requirements.

With the approach of having LAN QoS as you adviced I think I can atleast prioritize the inside traffic of the data center and whatever is going outside.

Many thanks
0
 
LVL 12

Expert Comment

by:ryan80
ID: 39271353
You  can certainly prioritize the traffic at the egress point, which will send out the important traffic first if there is contention, but once on the internet there is no guarantee.
0

Featured Post

Get proactive database performance tuning online

At Percona’s web store you can order full Percona Database Performance Audit in minutes. Find out the health of your database, and how to improve it. Pay online with a credit card. Improve your database performance now!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month14 days, 10 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question