This section provides an example for configuring hierarchical traffic policies to control bandwidth of different departments, different employees in each department, and different services used by employees.
As shown in Figure 1, an enterprise has department A. Department A includes sales and R&D employees. The sales employees need to use email and ERP applications.
The enterprise requires to enable the bandwidth management function on the FW to assign bandwidth resources available for department A and further assign these bandwidth resources to the sales employees in the department, so that the email and ERP traffic of the sales employees can be properly forwarded. Specific requirements are as follows:
[FW] traffic-policy [FW-policy-traffic] profile profile_dep_a [FW-policy-traffic-profile-profile_dep_a] bandwidth maximum-bandwidth whole downstream 60000 [FW-policy-traffic-profile-profile_dep_a] quit
In the example, user authentication configuration for department A (dep_a) and sales employees in department A (dep_a_sale) has been completed.
[FW-policy-traffic] rule name policy_dep_a [FW-policy-traffic-rule-policy_dep_a] source-zone trust [FW-policy-traffic-rule-policy_dep_a] destination-zone untrust [FW-policy-traffic-rule-policy_dep_a] user user-group /default/dep_a [FW-policy-traffic-rule-policy_dep_a] action qos profile profile_dep_a [FW-policy-traffic-rule-policy_dep_a] quit
[FW-policy-traffic] profile profile_dep_a_sale [FW-policy-traffic-profile-profile_dep_a_sale] bandwidth maximum-bandwidth whole downstream 30000 [FW-policy-traffic-profile-profile_dep_a_sale] quit
[FW-policy-traffic] rule name policy_dep_a_sale parent policy_dep_a [FW-policy-traffic-rule-policy_dep_a_sale] source-zone trust [FW-policy-traffic-rule-policy_dep_a_sale] destination-zone untrust [FW-policy-traffic-rule-policy_dep_a_sale] user user-group /default/dep_a_sale [FW-policy-traffic-rule-policy_dep_a_sale] action qos profile profile_dep_a_sale [FW-policy-traffic-rule-policy_dep_a_sale] quit
[FW-policy-traffic] profile profile_dep_a_sale_email [FW-policy-traffic-profile-profile_dep_a_sale_email] bandwidth guaranteed-bandwidth whole downstream 20000 [FW-policy-traffic-profile-profile_dep_a_sale_email] quit
The following example describes the bandwidth management configuration for Outlook Web Access and LotusNotes. You can specify other P2P services as required.
[FW-policy-traffic] rule name policy_dep_a_sale_email parent policy_dep_a_sale [FW-policy-traffic-rule-policy_dep_a_sale_email] source-zone trust [FW-policy-traffic-rule-policy_dep_a_sale_email] destination-zone untrust [FW-policy-traffic-rule-policy_dep_a_sale_email] application app LotusNotes OWA [FW-policy-traffic-rule-policy_dep_a_sale_email] action qos profile profile_dep_a_sale_email [FW-policy-traffic-rule-policy_dep_a_sale_email] quit
This section provides only the script related to the example.
# sysname FW # interface GigabitEthernet0/0/1 undo shutdown ip address 1.1.1.1 255.255.255.0 # interface GigabitEthernet0/0/3 undo shutdown ip address 10.3.0.1 255.255.255.0 # firewall zone trust set priority 85 add interface GigabitEthernet0/0/3 # firewall zone untrust set priority 5 add interface GigabitEthernet0/0/1 # traffic-policy profile profile_dep_a bandwidth maximum-bandwidth whole downstream 60000 profile profile_dep_a_sale bandwidth maximum-bandwidth whole downstream 30000 profile profile_dep_a_sale_email bandwidth guaranteed-bandwidth whole downstream 20000 rule name policy_dep_a source-zone trust destination-zone untrust user user-group /default/dep_a action qos profile profile_dep_a rule name policy_dep_a_sale parent policy_dep_a source-zone trust destination-zone untrust user user-group /default/dep_a_sale action qos profile profile_dep_a_sale rule name policy_dep_a_sale_email parent policy_dep_a_sale source-zone trust destination-zone untrust application app LotusNotes application app OWA action qos profile profile_dep_a_sale_email