QoS Egress going over the limit.

Options
PeterUK
PeterUK Posts: 2,767  Guru Member
First Anniversary 10 Comments Friend Collector First Answer
edited April 2021 in Security

Ok not many will see this issue but I do so I'm showing how to test this.

USG 60 WAN1 and DMZ in a bridge WAN1 Egress set to 5056Kbps and DMZ to 65536Kbps

The tests most do is you download you download you upload you upload but what if you download and upload at the same time this is where the QoS Egress goes over the limit and hits my ISP non-QoS limit.

Using a download manager to download a big file with 4 connections to the file and Speedtest By Ookla as your downloading the big file and when Speedtest By Ookla starts the upload test is where the problem starts.

So anyone else seeing this?

«13

Comments

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,454  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @PeterUK,
    I try the same scenario to simulate the bridge interface BWM, I got the same issue, keep you updated.
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,454  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @PeterUK,
    I test this scenario again on local lab,
    1) Set egress 5056 kbps on Wan and DMZ interface.
    2) Bridge both interface to BR0.
    3) Run 4 http download threads by download manger.
    4) Run the Speed test at the same time.
        Check the PC NIC bandwidth usage, Downstream is around 5.2Mbit/s and the upstream is around   5.0Mbits/s

     Is my way of testing same as yours? How many bandwidth is going over the limit?


  • PeterUK
    PeterUK Posts: 2,767  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited May 2018
    Options

    My ISP limits me to 5250000 bps or 5126.95Kbps to check the Egress limit I use the USG port statistics by setting the poll interval to 1 then convert to Kb here on WAN1 Tx B/s:

    https://www.aqua-calc.com/rate/bandwidth-calculator

    When I upload only its 5046.13Kps

    When I upload and download I get the Egress trying to send (or does send) 5341.69Kps which buffers my connection and my BQM spikes.

    thanks

  • PeterUK
    PeterUK Posts: 2,767  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited May 2018
    Options

    Back with V4.25(AAKY.0) it limits a bit better

    Making a rule with BWM enabled for

    BWN type = shared

    user = any

    incoming Interface = any

    outgoing interface = any

    source = any

    destination = any

    service object a group with (any TCP, any UDP, ICMP)

    guaranteed bandwidth

    Inbound 128kbps check box maximize bandwidth usage

    outbound 128kbps check box  maximize bandwidth usage

    Running a test with upload and download at the same time it does slightly Egress going over the limit 5167.52Kbps but is better then V4.31.

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,454  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @PeterUK,
    It is traffic shaping retains excess packets in a queue and then schedules the excess for later transmission over increments of time, smetimes It will go over the limit slightly.




  • PeterUK
    PeterUK Posts: 2,767  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited May 2018
    Options

    No it really is going over the limit when downloading and uploading even if I Egress slower it still goes over the limit.

    Even if I Egress at 4032Kbps it going over 5056Kbps !


  • PeterUK
    PeterUK Posts: 2,767  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    At 3008Kbps (set the limit and rebooted) its Tx Egress at 5008.19Kbps when downloading and uploading.

    But if you want to ignore then I go back to V4.25 where it limits better then V4.31 because I know something has changed and I just have to wait for the firmware team to fix it.

  • PeterUK
    PeterUK Posts: 2,767  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    With V4.25 set to 3008Kbps (set the limit and rebooted) the Tx Egress is 3199.97Kbps when downloading and uploading much better then V4.31.



  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,454  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @PeterUK,
    If you verified the QOS Tx&Rx by Monitor > System Status > Port Statistics, It would be a little inaccurate, since it is physical interface Tx/Rx Statistics, not just only intranet host to Bridge interface traffic.
    It also include any Broadcast, Multicast, ARP packets receive/transmit from port 1.
    Can you do one more testing in the same condition and monitor the Tx/Rx value on PC(Install tool on PC to monitor Tx/Rx), instead of USG physical port interface Statistics.




  • PeterUK
    PeterUK Posts: 2,767  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited May 2018
    Options

    You say inaccurate? Its more inaccurate checking by PC because you send more then the USG (should) Egress out of the Tx port so to be fair its more accurate by the ports statistics by Tx sent per second.

    But I'm telling you now something has changed between V4.25 and V4.31 for the QoS BWM.

    I have a GS2210 with Port Status showing Tx/Rx KB/s how about I use that to show its going over the egress limit after the USG?

Security Highlight