×

UNMS - Suspension, Traffic Shaping and Aggregation

Overview

Readers will learn more about the UNMS Suspension and Traffic Shaping features. These advanced networking features strongly focus on allowing ISPs to manage and influence the traffic of clients located in the network. 

NOTES & REQUIREMENTS:
  • Applicable to the latest UNMS release version.
  • More information on the Ubiquiti Network Management System can be found on the UNMS website.
  • Traffic Shaping for ONU devices is supported starting from the v1.1.0 UNMS version.
  • See the Global Features for Networks article for more information on the UNMS advanced network features.

Table of Contents

  1. Introduction
  2. Configuring Traffic Shaping
  3. CRM: Service Plan Aggregation
  4. Configuring Suspension
  5. Related Articles

Introduction

Back to Top

Adding an EdgeRouter device as a UNMS Gateway router allows you to easily configure advanced networking features such as Traffic Shaping, NetFlow, and Suspension.

  • Traffic Shaping Limits the upload and download speed of client devices to a specific value.
  • NetFlow Collects IP network traffic statistics. See the NetFlow article for more information.
  • Suspension Allows an administrator to (temporarily) suspend the network services of a client or customer.  See the Suspension article for more information.
NOTE: In UNMS version v0.14.0+ and v1.0.0+, it is recommended to perform both Suspension and Traffic Shaping through the UNMS Gateway router.Alternatively, it is possible to shape the traffic on Ubiquiti CPE devices as well.

On older versions of UNMS (v0.14.x), Traffic Shaping is manually configured directly on Client Sites. On the newer versions (v1.0.0+). it is possible to use the new integrated CRM module to manage Suspension and Traffic Shaping according to ISP business plans and tariffs. The management is performed through a service created in CRM and paired with a client site. 

In order to manage traffic shaping, UNMS gathers all IP addresses of all devices attached to a Client Site. Then it discards those IP addresses which are not in the defined internal network range (which can be configured in the  settings.png  Settings > Network > Addresses section). All management IP addresses are discarded as well at this point. For all remaining IP addresses, a rule is created on the gateway with a specified data transfer speed limit. In the case of Gateway + CPE traffic shaping, those rules are pushed to a specific CPE device, which connects a Client Site to its parent Site.

NOTE:Shaping or Suspension rules are in effect regardless of what type/brand of device is downstream (on the side of your client).

UNMS monitors any IP changes on shaped or suspended devices and alters the rules on the gateway or CPE accordingly. Please note it can take several minutes to distribute the changed rules through the system. 

Configuring Traffic Shaping

Back to Top

There are many ways to perform Traffic Shaping on a network. UNMS focuses on two of them:

Gateway Only All traffic shaping rules are configured on the main gateway. It is important to make sure all internet connections are going through that device in order to make the traffic shaping work correctly. UNMS supports multiple gateways with the expectation that there won't be dozens of them. We recommend using an EdgeRouter with the latest v2.0.x firmware as the UNMS Gateway router.

Gateway + CPE It is not possible to configure the Traffic Shaping feature only on CPE devices as that may lead to conflicts with gateway settings. The gateway has to be aware that traffic shaping is enabled. It is important to mention that each traffic shaping method has its own pros and cons. Traffic shaping in UNMS is done on WLAN (egress) and LAN (egress). Supported CPE devices for this version are airMAX AC, airMAX M, and airFiber in both router and bridge modes. 

Follow the steps below to enable the Traffic Shaping feature from UNMS:

GUI: Access the UNMS Controller Web Portal.

1. Navigate to the  settings.png  Settings > Network section.

2. Edit the existing UNMS Gateway router or add a new gateway.

3. Enable the Traffic Shaping feature by changing the Allow Traffic Shaping slider to ON.

4.    Define the max upload/download gateway WAN capacity. If this is not specified, the maximal physical capacity of the WAN interface is assumed.

5. The specific limits are configured per Service Plan in the CRM module. Navigate to the CRM > System > Service plans & Products section to add or modify a service plan.

6. Navigate to the CRM > Clients > Select client > Select service plan to associate a client with a service plan.

7. It is possible to set up limits for both download and upload, as well as aggregation. See the section below for more information on the CRM Service Plan Aggregation option.

CRM: Service Plan Aggregation

Back to Top

NOTE:Aggregation is set automatically starting from the UNMS v1.2.0 release. UNMS will attempt to find the correct aggregation for the optimal line utilization as well as the gateway performance.

It is still possible to manually configure the aggregation value if needed.

Aggregation defines the minimal guaranteed throughput for each client at any given moment. For example, if there is a tariff with 125 Mbps limit and the aggregation is set to 5, then each client will have 25 Mbps (125 / 5) of guaranteed throughput. For aggregation to work correctly, the sum of all guaranteed speeds for all users has to be lower than the total available throughput on the UNMS Gateway router.

The example below uses two tariffs:

  • Standard 100/10 Mbps Download/Upload with 80 aggregation.
  • Premium 100/10 Mbps Download/Upload with 7 aggregation.

In this example, there are 200 clients that use the Standard tariff and 5 clients that use Premium. The total throughput this ISP bought and which is available for sharing through the WAN interface is 800Mbps.

As a first step, it is necessary to check if the intended setup is correct by calculating the values:

  • Standard offers 1.25Mbps guaranteed speed (100/80) and there are 200 clients. This equals to 200 * 1.25 = 250Mbps for all clients.
  • Premium offers 14.28Mbps guaranteed speed (100/7) and there are 5 clients. This equals to 5 * 14.28 = 71.4Mbps for all clients.
  • Combined there is 321.4Mbps used on a WAN interface that support up to 800Mbps, so this setup is valid.
  • If the amount of Premium users was the same as Standard, the total required throughput would be (200 * 1.25) + (200 * 14.28) = 250 + 2856 = 3106Mbps = 3.1Gpbs. This setup is not valid and the gateway will display the overloaded warning.

For the customers, the aggregation settings mean that:

  • Each customer with the Standard service will have at least 1.25Mbps download and 125Kbps upload guaranteed even if everybody is fully utilizing their links. If the overall utilization is low, it is possible to download as much as 100Mbps with this tariff.
  • Each customer with the Premium service will have at least 14.28Mbps download and 1.42Mbps upload guaranteed even if everybody is fully utilizing their links. If the overall utilization is low, it is possible to download as much as 100Mbps with this tariff.

It would be rather difficult to recalculate the aggregation each time the user count changes. Therefore the aggregation is calculated automatically on the v1.2.0+ UNMS version. UNMS will automatically calculate the optimal aggregation values that provide maximal throughput for clients while not overloading the router. When the number of clients changes or when other aggregations are manually reconfigured, UNMS immediately recalculates the optimal aggregation values and pushes it to the UNMS Gateway router.

Follow the steps below to configure aggregation manually for a Service plan:

GUI: Access the UNMS Controller Web Portal.

1. Navigate to the CRM > System > Service plans & Products section to add or modify a service plan.

2. Expand the Set traffic shaping details option and specify the aggregation value.

NOTE:A blank value set in the service plan Aggregation field means that the aggregation is automatically calculated.

Configuring Suspension

Back to Top

The UNMS Suspension feature allows an administrator to (temporarily) suspend the network services of a client or customer. This feature identifies clients by their IP address and prevents them from accessing the internet or other networks, with the exception of some previously defined network services.

The feature relies on the UNMS Gateway role that is assigned to an EdgeRouter device. It is recommended to use the latest UNMS version and the EdgeRouter v2.0.x EdgeOS firmware when using Suspension. Another requirement for Suspension is that customer internet connectivity flows through that specific gateway. Since there can be more than one gateway defined in UNMS it is vital to make sure this is correctly set up.

NOTE: The suspended Client Site and devices attached to it will not disconnect from UNMS and it will be possible to manage them remotely despite the suspension.

Admins may set up other IP addresses, which customers are allowed to visit despite being in the suspended state. This is useful to redirect customers to a specific website that offers payment services or a portal that they can use to communicate with the ISP. When a suspended customer tries to visit any page outside of the mentioned whitelist, the traffic is redirected to a suspension page with information about the suspension and an option to temporarily cancel it in order to allow payment. A suspended client can also still reach UNMS since this default exception is created automatically.

Follow the steps from the dedicated Suspension article for more information on configuring the UNMS Suspension feature on an EdgeRouter that is assigned the UNMS Gateway role.

NOTE:When suspended users visit a HTTP page they are redirected to the suspension page. In some cases, this doesn't work for HTTPS pages due to the security settings.

Related Articles

UNMS - Global Features for Networks

UNMS - NetFlow

EdgeRouter - Suspension

Was this article helpful?
36 out of 40 found this helpful
Can't find what you're looking for?
Visit our worldwide community of Ubiquiti experts for more answers
Visit the Ubiquiti Community