Is it possible to use a pf firewall (with ALTQ or other mechanism) to configure bandwidth utilization such that packets from IP addresses who caused a high bandwidth utilization during the last minute or so get a lower priority?
I have examined the ALTQ documentation, but I found no way to do that.
Background: we sometimes have the problem that our Internet connection is slowed down by users doing bulk data transfers (either via FTP, via Windows network shares, via IPSEC tunnels, ...). It is not possible to reserve bandwidth for particular protocols (or to prioritize certain protocols), because we use many IPSEC tunnels, and there are so many different protocols in use that are equally important.
Therefore, I would simply like to slow down packets from users who are causing high traffic, because they expect that they have to wait some time, and it does not matter whether or not the bulk transfer takes 10% more time.
Many thanks in advance for any hints.
I have examined the ALTQ documentation, but I found no way to do that.
Background: we sometimes have the problem that our Internet connection is slowed down by users doing bulk data transfers (either via FTP, via Windows network shares, via IPSEC tunnels, ...). It is not possible to reserve bandwidth for particular protocols (or to prioritize certain protocols), because we use many IPSEC tunnels, and there are so many different protocols in use that are equally important.
Therefore, I would simply like to slow down packets from users who are causing high traffic, because they expect that they have to wait some time, and it does not matter whether or not the bulk transfer takes 10% more time.
Many thanks in advance for any hints.