256
14.1.2.5-C
Routing
Policy Routing
On this tab you can configure static routing entries. You can add conventional routes,
considering only the packet's destination, but also extended rules which include source
addresses, protocol and port numbers (policy based routing).
Static routes must be added for networks behind the peer. Specify the network address
and the netmask of this remote network - this will automatically instruct the SX-GATE
firewall to accept the network on this interface.
Rules for specific protocols or sources come into play if multiple internet links are
available. One could for instance direct web traffic via an ADSL link while all the other
traffic like emails and VPN uses an SDSL line.
The evaluation order is not based on the order in the list. The priority depends on how
specific a rule is, taking in account the rules configured across all devices. Routes with
all three parameters defined (i.e. protocol, source and destination) will be considered
first. Rules with a destination take precedence over rules with protocol. These in turn
have a higher priority than rules with a source. Within source and destination, rules
are sorted by descending netmasks. The evaluation order of overlapping protocol
specifications is not defined.
14.1.2.5-D
Bandwidth management / QoS
For bandwidth management you have to fill in the available bandwidth. Uplink and
downlink may be different (ADSL). Leave empty to disable bandwidth management on
this interface. If you enter only one value, either for uplink or for downlink, bandwidth
management will apply to packets in that direction only.
Specifying a wrong bandwidth can cause severe connection
problems, especially if the actual bandwidth is lower than the
configured one. Please ask your provider if you are uncertain.
Outbound bandwidth (uplink)
Enter the uplink bandwidth. For asymmetric connections this is usually the lower value.
Bandwidth management will then process all outbound packets on this interface. The
direction of the corresponding connection (inbound or outbound) doesn't matter.
Inbound bandwidth (downlink)
Enter the downlink bandwidth. For asymmetric connections this is usually the higher
value. Bandwidth management will then process all inbound packets on this interface.