Creating queues for the DMZ interface

Go to Security policy > Quality of service > Queues tab.

Creating the default queue for the DMZ interface

  1. Click on Add.
  2. Select Class Based Queuing (CBQ).
  3. Name the queue (DEF_DMZ_Q in this example).
  4. In the Guaranteed bandwidth line, indicate the desired value for bandwidth reservation (100 Mbit/s in this example).
  5. In the Max bandwidth line, leave the value suggested by default (10 Gbit/s).
  6. In the Guaranteed rev. line, indicate the desired value for bandwidth reservation (100 Mbit/s in this example).
  7. In the Max rev. line, leave the value suggested by default (10 Gbit/s).
  8. Confirm by clicking on Apply.

Creating the acknowledgment (ACK) queue for the DMZ interface

In this example, the link connected to the DMZ interface displays maximum bandwidth of 1 Gbit/s: the acknowledgment (ACK) queue will therefore be 50 Mbit/s (reservation equivalent to 5% of the link's maximum bandwidth).

  1. Follow the steps explained in the procedure Creating the default queue for the DMZ interface with the following values:
Queue type Class Based Queuing
Name DEF_DMZ_ACK_Q
Guaranteed bandwidth 50 Mbit/s
Max bandwidth unlimited
Guaranteed rev. 50 Mbit/s
Max rev. unlimited

The grid of the QoS queues set in this example will therefore look like this:

  1. Confirm changes to the QoS configuration by clicking on Apply.