Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.107
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Bandwidth Management")}}

Bandwidth Management

{{ $t('productDocDetail.updateTime') }}: 2026-02-05

Bandwidth management is to control the traffic sizes of various web applications by building bandwidth management channels.

The bandwidth management system provides the functions of bandwidth guarantee and limitation. The former ensures the access bandwidths of important applications, whereas the latter restricts the total inbound and outbound bandwidths of user groups/users and those of various applications.

The bandwidth management system also provides the traffic sub-channel function, which allows for a more refined allocation of channel traffic by building traffic sub-channels as required.

Basic Concepts

Bandwidth Channel: Divide the bandwidth of the whole line into several parts by percentage and allocate different bandwidth resources by application type or user group. By their functions, the bandwidth channels are divided into the guaranteed channel and the limited channel.

Limited channel: Set the maximum flow rate of the channel. In the case of a busy network, the bandwidth occupied by the channel does not exceed the preset maximum bandwidth.

Guaranteed channel: Set both the maximum and minimum bandwidths of the channel. In the case of a busy network, this channel ensures that the bandwidth's channel is not smaller than the preset minimum bandwidth.

Link: Establish a correspondence between the device's physical network interfaces and the "Links" in bandwidth channels, specifying the interface for outbound data that can match the bandwidth management channel.

Bandwidth Channel Matching and Priority

If the status of the bandwidth management system is Enabled, data going through the device is matched to a bandwidth channel based on data details. The rules for matching involve the user group/user, IP address, application category, effective time, destination IP, and group. Data packets that meet all the rules will match the channel.

Data with the same details will only be matched to a bandwidth management policy. The matching sequence of the flow channel is matched from top to bottom, so you need to put the channel with more detailed matching conditions on the top when setting.