FVS338 ProSafe VPN Firewall 50 Reference Manual

Bandwidth limiting for outbound traffic is done on the available WAN interface in both the single port and Auto Rollover modes. Bandwidth limiting is handled on the user-specified interface in Load Balancing mode.

Bandwidth limiting for inbound traffic is handled on the LAN interface for all WAN modes. Bandwidth limiting does not apply to the DMZ interface.

Example: When a new connection is established by a device, the device will locate the firewall rule corresponding to the following connections.

If the rule has a bandwidth profile specification, then the device will create a bandwidth class in the kernel.

If multiple connections correspond to the same firewall rule, they will share the same class.

An exception occurs in the case of an individual type bandwidth profile if the classes are per source IP. The source IP is the IP of the first packet of the connection.

For the outbound rules the source IP will be LAN-side IP.

For inbound rules the source IP will be the WAN-side IP.

The class is deleted when all the connections using the class expire.

To add a Bandwidth Profile:

1.Select Security from the main menu and Bandwidth Profile from the submenu. The Bandwidth Profile screen will display.

Figure 4-20

The Bandwidth Profile table lists the currently defined bandwidth profiles:

Name: Displays the user-defined name for this bandwidth profile.

Bandwidth Range: Displays the range for the bandwidth profile.

Type: Displays the type of bandwidth profile.

Direction: Displays the direction of the bandwidth profile.

Firewall Protection and Content Filtering

4-31

v1.0, March 2008

Page 87
Image 87
NETGEAR manual FVS338 ProSafe VPN Firewall 50 Reference Manual