Scheduled Throttling with pfSense

By · Published · pfsense, networking, apple, howto

Apple has launched a new Photos App for OS X, along with the ability to upload your entire library to iCloud. And with prices that are so cheap, there's almost no reason not to. $3.99 a month is cheap insurance to know that every photo I've ever taken of my family won't be wiped out in a tornado.

But with this comes a problem - namely, how do you upload a 150 gigabytes of photos over a 5 megabit network connection? Well, you wait a really long time for it to upload. Which is fine, really, because I'm not in any particular hurry to finish. But, once I started the upload, I noticed that surfing the web became pretty much impossible because the upload to iCloud was saturating my upstream bandwidth.

What I needed was a way to throttle the iCloud upload. I really don't care if that adds a couple more hours or days to the upload. I just need to be able to surf from other devices without problems. But at the same time, I'm not using my connection in the middle of the night. There's no reason it could't go full bore overnight.

And this is where pfSense comes in.

Start by creating a schedule:

  1. Go to Firewall -> Schedules. Add a new schedule.
  2. Give it a name. I called mine "Nighttime."
  3. Click the headers of each day of the month in the calendar. This will apply it to every day.
  4. Set the start time to 8:00 and the end time to 23:59. This means I want the schedule to be active between 8am and about midnight, which mirrors my usage patterns. You can adjust this as needed.
  5. Click "Add Time".
  6. Click "Save".

Next, create a limiter:

  1. Go to Firewall -> Traffic Shaper. Click the Limiter tab. Click "Create a new limiter".
  2. Click "Create a new limiter".
  3. Check "Enable limiter and its children".
  4. Give it a name. I called my first one "3mb-source" (limit outbound to 3 megabit).
  5. Under bandwidth, set it to whatever you want the limit to be (in my case, 3 and Mbit/s) and select the schedule you just created from the dropdown.
  6. Under mask, set "Source addresses".
  7. Click "Save."

Now, apply the rule.

  1. Go to Firewall -> Rules. Select the LAN tab. Create a new rule. Configure it as follows:
    • Interface: LAN
    • Source: Single host or alias, and the IP address of your uploading machine.
  2. Under "Advanced", click "In/Out". In the first dropdown, select the limiter you made above.
  3. Click "Save."
  4. Now, you need to order the rules so that this rule is applied first. Check the box next to the rule you just created, then click the little left-pointing arrow next to the top rule, right underneath the anti-lockout rule.
  5. At the top, click "Apply Changes".

That's it! Your upstream bandwidth from the uploading machine is now limited to whatever you set it to, but only during the hours specified by your schedule.

Now, if you want extra credit, you could try to identify the upstream server's IP address and craft a rule that only applies the limit to outbound packets to iCloud. Another approach would be to use QoS and de-prioritize packets from the machine. But that was overkill for me. This solution was "good enough" for a temporary measure to keep my network working while the uploading occurs.

( Comments )

Did something I wrote help you out?

That's great! I don't earn any money from this site - I run no ads, sell no products and participate in no affiliate programs. I do this solely because it's fun; I enjoy writing and sharing what I learn.

All the same, if you found this article helpful and want to show your appreciation, here's my Amazon.com wishlist.


Related Posts

Installing the Ubiquiti UniFi Controller Software on pfSense 2.2

More collectd and pfSense Fun!


comments powered by Disqus