Martin, Actually this is exactly what I want. I want to shape the entire OpenVPN tunnel entirely. This is because I will only be passing VoIP traffic within this tunnel. Therefore, if I want to run my VoIP OpenVPN tunnel over the standard port 1194 then I would like to shape all traffic on port 1194. I have tried this by using the wizard, specifying I want to shape VoIP, and then going and modifying the VoIP shaping rules to shape only port 1194. Unfortunately, I never see the traffic in the VoIP queue when I place calls to our remote offices over the OpenVPN tunnel. Thanks.
Mike Fuchs, Martin wrote: > The general problem is not solved until now - encrypted tunnels cannot be > shaped... > There's the possibility to shape a whole OpenVPN tunnel (clientside) for > outgoing traffic, but I believe this is not what wou really want... > > What you are planning is some sort of traffic shaping on port based rules. > > It might be possible to do so, but perhaps you better ask scott for this when > he's back from bsdcan... > > Regards, > > Martin > > -----Ursprüngliche Nachricht----- > Von: Mike Lee [mailto:[EMAIL PROTECTED] > Gesendet: Donnerstag, 17. Mai 2007 16:40 > An: support@pfsense.com > Betreff: [pfSense Support] Shaping OpenVPN Tunnels (Take two) > > Hello Everyone, > > I did some searching and found this previous discussion on shaping > OpenVPN tunnels: > > http://forum.pfsense.org/index.php?PHPSESSID=836df07da7c9becd9259e22e1847c7ae&topic=3013.0 > > Basically the discussion ended with, that you cannot shape the > OpenVPN tunnels because openvpn uses the TUN interface and the shaper > looks for traffic on the LAN interface heading towards the WAN to > shape. My question is, since this discussion is somewhat old, has there > been any more progress/talk on getting the OpenVPN tunnels to shape > properly? > I would like to be able to shape them because I have some remote > offices and plan on using OpenVPN tunnels for VoIP. I know you cannot > shape traffic within VPN tunnels because they are encrypted, but I am > planning on using specific ports for certain tunnels to pass only VoIP > traffic through and shaping those OpenVPN ports. > Thanks in advance. > > Mike Lee > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [EMAIL PROTECTED] > For additional commands, e-mail: [EMAIL PROTECTED] > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [EMAIL PROTECTED] > For additional commands, e-mail: [EMAIL PROTECTED] > > --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]