Introduction to QoS
R82 QoS Administration Guide
Introduction to QoS
| Important - From R81, Security Gateway also refers to a VSX Virtual System. |
The Check Point QoS Solution
QoS is a policy based bandwidth management solution that lets you:
- Prioritize business-critical traffic, such as ERP, database and Web services traffic, over lower priority traffic.
- Guarantee bandwidth and control latency for streaming applications, such as Voice over IP (VoIP) and video conferencing.
- Give guaranteed or priority access to specified employees, even if they are remotely accessing network resources.
You deploy QoS with the Security Gateway.
QoS is enabled for both encrypted and unencrypted traffic.
| Item | Description |
|---|---|
| 1 | SmartConsole |
| 2 | Security Management Server |
| 3 | QoS Policy |
| 4 | Security Gateway with QoS Software Blade |
| 5 | Internet |
| 6 | Internal network |
QoS leverages the industry's most advanced traffic inspection and bandwidth control technologies. Check Point patented Stateful Inspection technology captures and dynamically updates detailed state information on all network traffic. This state information is used to classify traffic by service or application. After traffic has been classified, QoS applies an innovative, hierarchical, Weighted Fair Queuing (WFQ) algorithm to accurately control bandwidth allocation.
| Note - When the QoS Software Blade is disabled, the Security Gateway does not modify DSCP bits in packets that pass through. |
Features and Benefits
QoS gives these features and benefits:
- Flexible QoS policies with weights, limits and guarantees
- Integration with the Security Gateway
- Performance analysis
- Integrated DiffServ support
- Integrated Low Latency Queuing
- No need to deploy separate VPN, Firewall and QoS devices
- Proactive management of network costs
- Support for end-to-end QoS for IP networks
- CoreXL and SecureXL support
- VSX Support
QoS Policy Types
This release includes two QoS Policy types:
- Express - Quickly create basic QoS Policies
- Recommended - Create advanced Policies with the full set of QoS features
This table shows the difference between the Recommended and Express policy types.
| Features | Recommended | Express | To learn more |
|---|---|---|---|
| IPv6 Support | |||
| Weights | Weight | ||
| Logging | Overview of Logging | ||
| Accounting | * | ||
| Support for hardware acceleration | |||
| High Availability and Load Sharing | |||
| Guarantees | |||
| (Per connection) | Guarantees | ||
| Limits (Per connection) | |||
| LLQ (controlling packet delay in QoS) | Low Latency Queuing | ||
| DiffServ | Differentiated Services (DiffServ) | ||
| Sub-rules | |||
| Matching by URI resources | |||
| Matching by DNS string | |||
| SecureXL support | |||
| CoreXL support | |||
| SmartLSM clusters | |||
| VSX Support |
To select a QoS Policy type:
- In SmartConsole menu, click Manage policies and layers.
- In the Manage Policies window, click New or select an existing Policy and then click Edit.
- Select QoS, and then select Recommended or Express.
Workflow
This topic shows a high-level workflow for creating an effective QoS Policy.
| Note: QoS must be enabled on the gateway and at least one interface for the workflow to succeed. If QoS is not enabled on at least one interface, Install Policy will fail. |
Do these steps in SmartConsole:
- Enable QoS for each applicable Security Gateway.
- Configure QoS Global Properties.
- Create or change a QoS Policy.
- Configure log collection and system monitoring for QoS.
- Publish the SmartConsole session.
Do these steps in SmartDashboard:
- Define the gateway networks, services and other related objects.
- Define QoS rules (basic and advanced).
- Configure specialized QoS features.
- Differentiated Services (DiffServ).
- Low Latency Queuing.
Go back to SmartConsole to do these steps:
- Publish the SmartConsole session.
- Install Policy.
| Note - In the SmartConsole Install Policy window, make sure you select QoS. |
Limitations
These limitations apply to Scalable Platforms:
- QoS is not supported when a Security Group is configured in the Layer 4 distribution mode.
- QoS policy is applied on each Security Group Member.