Rate limiting with QoS policies

To perform policy-based rate limiting, configure and deploy QoS policies to managed devices. Each QoS policy can target multiple devices; each device can have one deployed QoS policy at a time.

Only one person should edit a policy at a time, using a single browser window. If multiple users save the same policy, the last saved changes are retained. For your convenience, the system displays information on who (if anyone) is currently editing each policy. To protect the privacy of your session, a warning appears after 30 minutes of inactivity on the policy editor. After 60 minutes, the system discards your changes.

Procedure


Step 1

Choose Policies > Network policies > QoS.

Step 2

Click New Policy to create a new QoS policy and, optionally assign target devices; see Create a QoS policy.

You can also Copy (copy icon) or Edit (edit icon) an existing policy.

Step 3

Configure QoS rules; see Configuring QoS rules and QoS rule conditions.

The QoS policy editor lists each rule in evaluation order and displays a summary of the rule conditions and rate limiting configurations. Use the right-click menu to manage rules, including moving, enabling, and disabling them.

This feature is helpful in larger deployments. You can Filter by Device to display only the rules that affect a specific device or group of devices. You can also search for rules, and the system matches text entered in the Search Rules field to rule names and condition values, including objects and object groups.

Note

Properly creating and ordering rules is a complex but essential to effective deployment. Careful planning is necessary to prevent rules from preempting each other, requiring additional licenses, or containing invalid configurations. Icons in the interface represent comments, warnings, and errors. If issues exist, click Show Warnings to display a list. For more information, see Best practices for access control rules.

Step 4

Click Policy Assignments to identify which managed devices the policy targets; see Set target devices for a QoS policy.

Verify your choices, if you identified target devices during policy creation.

Step 5

Save the QoS policy.

Step 6

Since this feature must allow some packets to pass, configure your system to examine those packets.

Step 7

Deploy configuration changes.


The QoS policy is configured and deployed to the target devices, enabling policy-based rate limiting for network traffic.