![Fortinet FortiWAN Handbook Download Page 229](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088229.webp)
Bandwidth Management
Optional Services
Managing Bandwidth for Tunnel Routing and IPsec
Bandwidth Management is capable to control the original traffic that is encapsulated by Tunnel Routing or IPSec VPN.
Traffic that is going to be transferred outward through Tunnel Routing or IPSec VPN will be processed by Bandwidth
Management before encapsulating, and traffic that is transferred inward through Tunnel Routing or IPSec VPN is
controlled by Bandwidth Management after decapsulating. In other words, FortiWAN's Tunnel Routing and IPSec are
transparent to Bandwidth Management (and the corresponding BM log and statistics). Bandwidth Management can
only recognize the original applications (by matching a filter on the Service) that is going to be encapsulated or has
been decapsulated by Tunnel Routing or IPSec. The GRE and ESP packets generated by FortiWAN are invisible to
Bandwidth Management.
To control Tunnel Routing or IPSec transmission by Bandwidth Management, please make sure a Bandwidth
Management filter is defined correctly (on the source, destination and service) to match its original packets. If you
would like to control the overall Tunnel Routing or IPSec transmission no matter what the original services it is, try to
classify the traffic by its Source and Destination; the Source and Destination of the Routing Rules of Tunnel Routing,
or the Source and Destination of the Quick Mode selectors of IPSec Tunnel mode (See "
How to set up routing rules for
").
Traffic shaping by Bandwidth Manage takes place before Tunnel Routing and IPSec encapsulations. Traffic of an
application is counted together in BM logs no matter whether it is transferred through Tunnel Routing and IPSec, thus
you cannot recognize the traffic statistics as a Tunnel Routing (includes Tunnel Routing over IPSec Transport mode),
IPSec (Tunnel mode) or general transmission from the BM logs by the
PROTO
field (See "
"). As for
FortiWAN Reports, statistics of the traffic that is transferred through Tunnel Routing is indicated as GRE in the reports
but it is unable to drill down to the individual services. On the other hand, you cannot recognize a traffic as FortiWAN's
IPSec in the service report pages, traffic that is transferred through FortiWAN IPSec is separated into individual
services. See "
Traffic Statistics for Tunnel Routing and IPSec
" for the details.
Note that during the period system applying the configurations of Bandwidth Management (click the Apply button on
Web UI), traffic passing through FortiWAN will be blocked for a while.
FortiWAN Handbook
Fortinet Technologies Inc.
229