Solved

Juniper SSG5 firewall traffic-shaping problem

Posted on 2014-11-10
3
350 Views
Last Modified: 2014-12-20
We just installed a new broadband 100Mb. But the speed test only have around 50Mb after connected to the Juniper SSG5 firewall. However, if i change traffic-shaping mode to OFF, the speed test could have around 100Mb. Because i need traffic-shaping for some policies, the traffic-shaping mode is set to auto mode now.

After checking the policy base traffic-shaping and ingress policy of the interface rth0/5, there is no traffic shaping enabled. The speed only have 50Mb even i change the ingress and egress bandwidth to 100Mb manually as the screenshots.
Is there any other places i need to check for the traffic-shaping? Or how can i do the troubleshooting?
Thank you.
get-int-e05.jpg
traffic-shaping-int-e05.jpg
0
Comment
Question by:dickchan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 70

Accepted Solution

by:
Qlemo earned 500 total points
ID: 40434653
Did you check all policies for traffic shaping settings too?
0
 

Author Comment

by:dickchan
ID: 40439321
I disabled all polices which had traffic shaping, but still had the slow 50Mb problem.
But The speed is 100Mb  after if i disable nsrp HA settings, we had two ssg5 to formed the active/active HA zone.

Where can i check the  traffic shaping or bandwidth control for this case?
Thank you.
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 40439423
Now that you mention HA, I recall having read about issues like this. Check for firmware updates.
0

Featured Post

Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question