Project

General

Profile

Actions

Todo #16042

open

Feedback on pfSense® software Configuration Recipes — Configuring CoDel Limiters for Bufferbloat

Added by Daniel Marks 4 months ago. Updated 14 days ago.

Status:
New
Priority:
Very Low
Assignee:
-
Category:
Recipes
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:

Description

Page: https://docs.netgate.com/pfsense/en/latest/recipes/codel-limiters.html

Feedback: Suggestion regarding IPv6 in the "Create Floating Rule" section, I feel like the note about source matching should be expanded. I have noticed people are specifying "WAN" as the source for IPv6 address matching, when they really intended to match "LAN" addresses (attached screenshot). This common mistake means the actual source of most of their traffic (i.e. their LAN full of clients) will not have their traffic shaped. This is especially important when clients have publicly routable IPv6 addresses, as happy eyeballs will effectively bypass any rules you create on IPv4. I would probably go as far as creating a dedicated note at the bottom to remind users that have configured IPv6 that it is critical to implement traffic shaping over IPv6 if they have created rules for IPv4, as most endpoints on the internet that support IPv6 will use IPv6 by default.


Files

Screenshot 2025-02-10 at 7.46.00 PM.png (136 KB) Screenshot 2025-02-10 at 7.46.00 PM.png screenshot of example rules for dual stack networks Daniel Marks, 02/11/2025 01:06 AM
2025-05-17 at 11.51.20.png (111 KB) 2025-05-17 at 11.51.20.png Rob A, 05/17/2025 07:00 PM
Actions #1

Updated by Rob A 14 days ago

I was pointed at this but I don't think my issues are related. That said, the current docs do lead the user to the upper configuration I have in the screen shot, compared to the example above, which I have pasted to the lower part of the image. If I am correct this configuration is fine for single WAN but falls short for multi-WAN:

However, the real issue is probably the labyrinth that is the pfSense UI for setting FQ-CoDel. Given that the parameters are so simple (a very short line on CLI) the whole settings-only-appear-when-incomplete-settings-are-saved is not human friendly. Once the UI is reduced to a simple single page then differing options for multi-WAN should be offered here. Even EdgeRouters from back in the day had a simpler presentation than this for FQ-CoDel.

Actions

Also available in: Atom PDF