Solved

Implementing QoS without QoS-capable switches on remote site (Juniper SSG)

Posted on 2013-06-19
3
617 Views
Last Modified: 2013-06-24
Dear experts,

I have a situation where we have a main site (data center) and several remote sites (hub sites).


All sites have Juniper SSG firewall (5,20,140,520) with site-to-site VPN tunnels in between the DC and the remote sites.

In the data center all hardware server, OS, switches and firewall is fully QoS capable.
In the remote sites, some have low-cost netgear switches which have no or only basic QoS functionality.

I have the need to prioritize traffic since we are migrating to a VMWare Mirage platform for the clients while also we need to guarantee traffic for Oracle and client access gets priority over web/mail traffic.

My question basically is which of the below approaches is required or even an alternative please ?

Thanks in advance !

1) I need to implement QoS everywhere: Client -> switch -> firewall -> VPN -> firewall -> switch -> server
2) I need to implement QoS everywhere except the client: switch -> firewall -> VPN -> firewall -> switch
3) I can implement QoS only between the firewall (based on policy/port traffic) and the queue will be handled by the firewall's
0
Comment
Question by:ulensr
  • 2
3 Comments
 
LVL 12

Accepted Solution

by:
ryan80 earned 250 total points
ID: 39260168
First off, unless you have a private line/ MPLS there will be no QOS over the internet. once you hit the ISP there will be no qos.

now within your network you can implement qos as needed.  If you feel that there will be contention on the switch you can replace it with something that can handle qos. it really depends on how much traffic you have and how the switch handles it. However I would imagine that the bottle neck is going to be WAN connection not the switch, so I would treat that as secondary.

I have not worked with Junipers before but a quick search shows it to be fairly straight forward. http://www.howtonetworking.com/Routers/ssg4.htm
http://hydra.ck.polsl.pl/~helot/ipad/DayOne-Book/DO_Deploying_Basic_QoS.pdf

You should be able to set the priority of the traffic higher or give it a specific amount of bandwidth.
0
 

Author Closing Comment

by:ulensr
ID: 39270472
Thanks for your answer; although this doesn't completely solve my issue, your advice shows that technically there we do not meet the requirements.

With the approach of having LAN QoS as you adviced I think I can atleast prioritize the inside traffic of the data center and whatever is going outside.

Many thanks
0
 
LVL 12

Expert Comment

by:ryan80
ID: 39271353
You  can certainly prioritize the traffic at the egress point, which will send out the important traffic first if there is contention, but once on the internet there is no guarantee.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Before I go to far, let's explain HA (High Availability) and why you should consider it.  High availability is the mechanism used to provide redundancy to any service at the same site and appears as a single service to the users of that service.  As…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question